CVE-2025-4435
03.06.2025, 13:15
When using a TarFile.errorlevel = 0and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0in affected versions is that the member would still be extracted and not skipped.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases
Debian Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
jython |
| ||||||||
python2.7 |
| ||||||||
python3.11 |
| ||||||||
python3.12 |
| ||||||||
python3.13 |
| ||||||||
python3.9 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||
python3.10 |
| ||||||||||||||||
python3.11 |
| ||||||||||||||||
python3.12 |
| ||||||||||||||||
python3.13 |
| ||||||||||||||||
python3.4 |
| ||||||||||||||||
python3.5 |
| ||||||||||||||||
python3.6 |
| ||||||||||||||||
python3.7 |
| ||||||||||||||||
python3.8 |
| ||||||||||||||||
python3.9 |
|
Common Weakness Enumeration
References