USN-7989-1

Source
https://ubuntu.com/security/notices/USN-7989-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7989-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7989-1
Upstream
Related
Published
2026-02-02T02:41:26Z
Modified
2026-02-10T09:30:11.540544Z
Summary
python-internetarchive vulnerability
Details

Pengo Wray discovered that The Internet Archive Python Library incorrectly handled certain file paths when downloading files. An attacker could possibly use this issue to write files to arbitrary locations on the file system.

References

Affected packages

Ubuntu:Pro:20.04:LTS / python-internetarchive

Package

Name
python-internetarchive
Purl
pkg:deb/ubuntu/python-internetarchive@1.9.0-3ubuntu0.1~esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.0-3ubuntu0.1~esm1

Affected versions

1.*
1.8.1-1
1.8.5-1
1.9.0-2
1.9.0-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.9.0-3ubuntu0.1~esm1",
            "binary_name": "internetarchive"
        },
        {
            "binary_version": "1.9.0-3ubuntu0.1~esm1",
            "binary_name": "python3-internetarchive"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2025-58438"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7989-1.json"

Ubuntu:22.04:LTS / python-internetarchive

Package

Name
python-internetarchive
Purl
pkg:deb/ubuntu/python-internetarchive@1.9.9-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.9-1ubuntu0.1

Affected versions

1.*
1.9.9-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.9.9-1ubuntu0.1",
            "binary_name": "internetarchive"
        },
        {
            "binary_version": "1.9.9-1ubuntu0.1",
            "binary_name": "python3-internetarchive"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2025-58438"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7989-1.json"

Ubuntu:Pro:24.04:LTS / python-internetarchive

Package

Name
python-internetarchive
Purl
pkg:deb/ubuntu/python-internetarchive@3.5.0-1ubuntu0.1~esm1?arch=source&distro=esm-apps/noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1ubuntu0.1~esm1

Affected versions

3.*
3.3.0-1
3.5.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.5.0-1ubuntu0.1~esm1",
            "binary_name": "internetarchive"
        },
        {
            "binary_version": "3.5.0-1ubuntu0.1~esm1",
            "binary_name": "python3-internetarchive"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:24.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2025-58438"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7989-1.json"

Ubuntu:25.10 / python-internetarchive

Package

Name
python-internetarchive
Purl
pkg:deb/ubuntu/python-internetarchive@5.4.0-1ubuntu0.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1ubuntu0.1

Affected versions

5.*
5.2.1-1
5.3.1-1
5.4.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.4.0-1ubuntu0.1",
            "binary_name": "internetarchive"
        },
        {
            "binary_version": "5.4.0-1ubuntu0.1",
            "binary_name": "python3-internetarchive"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:25.10",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2025-58438"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7989-1.json"