CVE-2025-4435

EUVD-2025-16725
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
PSFCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Debian logo
Debian Releases
Debian Product
Codename
jython
bookworm
2.7.3+repack1-1
no-dsa
bullseye
2.7.2+repack1-3
not-affected
forky
2.7.3+repack1-1
fixed
sid
2.7.3+repack1-1
fixed
trixie
2.7.3+repack1-1
no-dsa
pypy3
bookworm
no-dsa
bullseye
7.3.5+dfsg-2+deb11u2
not-affected
bullseye (security)
7.3.5+dfsg-2+deb11u5
fixed
forky
7.3.20+dfsg-4
fixed
sid
7.3.20+dfsg-4
fixed
trixie
no-dsa
python2.7
bookworm
no-dsa
bullseye
2.7.18-8+deb11u1
fixed
trixie
no-dsa
python3.11
bookworm
3.11.2-6+deb12u6
no-dsa
bookworm (security)
3.11.2-6+deb12u3
fixed
bullseye
not-affected
trixie
no-dsa
python3.13
bookworm
no-dsa
bullseye
not-affected
forky
3.13.12-1
fixed
sid
3.13.12-1
fixed
trixie
3.13.5-2
no-dsa
python3.9
bookworm
no-dsa
bullseye
3.9.2-1
not-affected
bullseye (security)
3.9.2-1+deb11u5
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected
python3.4
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
python3.5
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected
python3.6
bionic
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.7
bionic
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.8
bionic
not-affected
focal
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.9
focal
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.10
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.11
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.12
jammy
dne
noble
Fixed 3.12.3-1ubuntu0.7
released
oracular
Fixed 3.12.7-1ubuntu2.2
released
plucky
dne
questing
dne
python3.13
jammy
dne
noble
dne
oracular
Fixed 3.13.0-1ubuntu0.3
released
plucky
Fixed 3.13.3-1ubuntu0.2
released
questing
not-affected
python3.14
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
Fixed 3.14.0-1
released