SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-4559

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a ..

CRITICAL 9.8EPSS 27.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 27.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
27.10% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
python/python
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.