Lack of data validation - Path Traversal In python-pip
Description
A flaw was found in the Python tarfile module. Extracting a crafted TAR archive with the tarfile.extract or tarfile.extractall functions could lead to a directory traversal vulnerability, resulting in overwrite of arbitrary files.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8.6 | 0:9.0.3-22.1.el8_6 | ||
rpm rhel8 | 0:9.0.3-23.el8 | ||
rpm rhel8.8 | 0:9.0.3-22.1.el8_8 | ||
rpm rhel6 | - | - | |
rpm rhel7 | - | - | |
rpm rhel9 | 0:21.2.3-7.el9 | ||
rpm rhel8 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | 0:3.6.8-56.el8_9 | ||
rpm rhel8.6 | 0:3.6.8-47.el8_6.4 |
1-10 of 19
10
Aliases
1. 2. 3.
References
1.