CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
- Affected products
- Alt Linux, Almalinux, Centos, Python Tarfile Module, Red Hat, Rocky Linux, Suse
- Python
- < 3.6.16, 3.8.17, 3.9.17, 3.10.12, 3.11.4
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 27.1% (98th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2007-08-28
CVE-2007-4559 at NVD
9 known exploits for CVE-2007-4559
Proof-of-concept code and exploit modules indexed by Sploitus