Lack of data validation - Path Traversal In python3.14
Description
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8 | - | - | |
rpm rhel6 | - | - | |
rpm rhel7 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
debian 13 | - | ||
debian 14 | - | ||
debian 13 | 3.13.5-2+deb13u3 |
1-10 of 15
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.