Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
| Software | From | Fixed in |
|---|---|---|
| python / python | 3.10.0 | 3.10.12 |
| python / python | 3.9.0 | 3.9.17 |
| python / python | 3.7.0 | 3.8.17 |
| python / python | - | 3.6.16 |
| python / python | 3.11.0 | 3.11.4 |