CVE-2025-4435
03.06.2025, 13:15
When using a TarFile.errorlevel = 0and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0in affected versions is that the member would still be extracted and not skipped.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jython |
| ||||||||||||
pypy3 |
| ||||||||||||
python2.7 |
| ||||||||||||
python3.11 |
| ||||||||||||
python3.13 |
| ||||||||||||
python3.9 |
|
Common Weakness Enumeration
References