CVE-2025-4435
EUVD-2025-1672503.06.2025, 13:15
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.9.23 | CNA |
| python | cpython | 3.10.0 ≤ 𝑥 < 3.10.18 | CNA |
| python | cpython | 3.11.0 ≤ 𝑥 < 3.11.13 | CNA |
| python | cpython | 3.12.0 ≤ 𝑥 < 3.12.11 | CNA |
| python | cpython | 3.13.0 ≤ 𝑥 < 3.13.4 | CNA |
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jython |
| ||||||||||||
| pypy3 |
| ||||||||||||
| python2.7 |
| ||||||||||||
| python3.11 |
| ||||||||||||
| python3.13 |
| ||||||||||||
| python3.9 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||
| python3.4 |
| ||||||||||||||||||
| python3.5 |
| ||||||||||||||||||
| python3.6 |
| ||||||||||||||||||
| python3.7 |
| ||||||||||||||||||
| python3.8 |
| ||||||||||||||||||
| python3.9 |
| ||||||||||||||||||
| python3.10 |
| ||||||||||||||||||
| python3.11 |
| ||||||||||||||||||
| python3.12 |
| ||||||||||||||||||
| python3.13 |
| ||||||||||||||||||
| python3.14 |
|
Common Weakness Enumeration
References