VDB
BDU%3A2025-06494
BDU%3A2025-06494
PUBLISHED
CVSS 9.699999809265137 CRITICAL
Уязвимость функции TarFile.extractall() и TarFile.extract() модуля tarfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю записывать произвольные файлы
Risk Scores
CVSS 2.0
9.699999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Fedora Project, Canonical Ltd., Python Software Foundation, АО "НППКТ", ООО «НЦПР» | Red Hat Enterprise Linux, openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Micro, Suse Linux Enterprise Server, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Public Cloud, SUSE Enterprise Storage, Fedora, SUSE Liberty Linux, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, Ubuntu, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, SUSE Linux Enterprise Module for Python 3, SUSE Linux Enterprise Server LTSS Extended Security, CPython, SUSE Linux Micro, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), МСВСфера |
Timeline
- Jun 9, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f url
- https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da url
- https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9 url
- https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a url
- https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e url
- https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a url
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a url
- https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01 url
- https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1 url
- https://github.com/python/cpython/issues/135034 url
- https://github.com/python/cpython/pull/135037 url
- https://github.com/python/cpython/pull/135084 url
- https://mail.python.org/archives/list/security-announce@python.org url
- https://github.com/python/cpython/tags url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://security-tracker.debian.org/tracker/CVE-2025-4517 url
- https://access.redhat.com/security/cve/cve-2025-4517 url
- https://ubuntu.com/security/CVE-2025-4517 url
- https://www.suse.com/security/cve/CVE-2025-4517.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2025-4517 url
…and 7 more