CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
Fixed
LOW (3.5)System detected CVE-2025-4435 with a risk of 1.72
- T
Tim Bastin fixed CVE-2025-4435
System updated the risk assessment from 1.72 to 3.45
System recalculated raw risk assessment
Reopen this vulnerability
Last calculated at:
Affected component
debian/python3.11