← Back to browse · API

CVE-2007-4559

Severity
CRITICAL
CVSS
9.8
EPSS
0.27095
Risk score
48.68
CISA KEV
No
PoC
No
Published
2007-08-28
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2007-4541, GHSA-GW9Q-C7GH-J9VM
Products
n/a:n/a n/a
Sources
euvd EUVD-2007-4541

Description

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

References