The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- python-unversioned-command as a component of Red Hat Enterprise Linux 10
- python3 as a component of Red Hat Enterprise Linux 10
- python3-debug as a component of Red Hat Enterprise Linux 10
- python3-devel as a component of Red Hat Enterprise Linux 10
- python3-idle as a component of Red Hat Enterprise Linux 10
- python3-libs as a component of Red Hat Enterprise Linux 10
- python3-test as a component of Red Hat Enterprise Linux 10
- python3-tkinter as a component of Red Hat Enterprise Linux 10
- python3.12.src as a component of Red Hat Enterprise Linux 10
- python as a component of Red Hat Enterprise Linux 6
- python-devel as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
