News

The vulnerability is in the Python tarfile package, in code that uses un-sanitized tarfile.extract() function or the built-in defaults of tarfile.extractall(). It is a path traversal bug that ...
A vulnerability in the Python programming language that ... the scope of the vulnerability transcends path traversal, allowing attackers remote code execution (RCE) abilities.
CVE-2007-4559 is a directory traversal vulnerability in the “extract” and “extractall” functions in Python’s tarfile ... ultimately achieving arbitrary code execution or control of ...