python: tarfile module directory traversal
Published Aug 28, 2007
9.8
CRITICALCVSS 3.1
EPSS 27.10%
Description
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
python-pip-0:9.0.3-23.el8
Fixed · RHSA-2023:7176
Red Hat Enterprise Linux 8
python-pip-0:9.0.3-23.el8
Fixed · RHSA-2023:7176
Red Hat Enterprise Linux 8
python3-0:3.6.8-56.el8_9
Fixed · RHSA-2023:7151
Red Hat Enterprise Linux 8
python3-0:3.6.8-56.el8_9
Fixed · RHSA-2023:7151
Red Hat Enterprise Linux 8
python3.11-0:3.11.5-1.el8_9
Fixed · RHSA-2023:7024
Red Hat Enterprise Linux 8
python3.11-pip-0:22.3.1-4.el8
Fixed · RHSA-2023:6914
Red Hat Enterprise Linux 8
python38-devel:3.8-8090020230810143931.d9f72c26
Fixed · RHSA-2023:7050
Red Hat Enterprise Linux 8
python38:3.8-8090020230810143931.d9f72c26
Fixed · RHSA-2023:7050
Red Hat Enterprise Linux 8
python39-devel:3.9-8090020230922213827.7484f1d1
Fixed · RHSA-2023:7034
Red Hat Enterprise Linux 8
python39:3.9-8090020230922213827.7484f1d1
Fixed · RHSA-2023:7034
Red Hat Enterprise Linux 8.6 Extended Update Support
python-pip-0:9.0.3-22.1.el8_6
Fixed · RHSA-2024:0374
Red Hat Enterprise Linux 8.6 Extended Update Support
python3-0:3.6.8-47.el8_6.4
Fixed · RHSA-2024:0430
Red Hat Enterprise Linux 8.8 Extended Update Support
python-pip-0:9.0.3-22.1.el8_8
Fixed · RHSA-2024:0587
Red Hat Enterprise Linux 9
python-pip-0:21.2.3-7.el9
Fixed · RHSA-2023:6694
Red Hat Enterprise Linux 9
python-pip-0:21.2.3-7.el9
Fixed · RHSA-2023:6694
Red Hat Enterprise Linux 9
python3.11-0:3.11.5-1.el9_3
Fixed · RHSA-2023:6494
Red Hat Enterprise Linux 9
python3.11-pip-0:22.3.1-4.el9
Fixed · RHSA-2023:6324
Red Hat Enterprise Linux 9
python3.9-0:3.9.18-1.el9_3
Fixed · RHSA-2023:6659
Red Hat Enterprise Linux 9
python3.9-0:3.9.18-1.el9_3
Fixed · RHSA-2023:6659
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-0:3.8.18-2.el7
Fixed · RHSA-2023:6793
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-pip-0:19.3.1-4.el7
Fixed · RHSA-2023:6793
Red Hat Enterprise Linux 6
python
Out of support scope
Red Hat Enterprise Linux 7
python
Out of support scope
Red Hat Enterprise Linux 7
python3
Out of support scope
Red Hat Enterprise Linux 8
python27:2.7/python2
Will not fix
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python-pip-0:9.0.3-23.el8 | Fixed | RHSA-2023:7176 |
| Red Hat Enterprise Linux 8 | python-pip-0:9.0.3-23.el8 | Fixed | RHSA-2023:7176 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-56.el8_9 | Fixed | RHSA-2023:7151 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-56.el8_9 | Fixed | RHSA-2023:7151 |
| Red Hat Enterprise Linux 8 | python3.11-0:3.11.5-1.el8_9 | Fixed | RHSA-2023:7024 |
| Red Hat Enterprise Linux 8 | python3.11-pip-0:22.3.1-4.el8 | Fixed | RHSA-2023:6914 |
| Red Hat Enterprise Linux 8 | python38-devel:3.8-8090020230810143931.d9f72c26 | Fixed | RHSA-2023:7050 |
| Red Hat Enterprise Linux 8 | python38:3.8-8090020230810143931.d9f72c26 | Fixed | RHSA-2023:7050 |
| Red Hat Enterprise Linux 8 | python39-devel:3.9-8090020230922213827.7484f1d1 | Fixed | RHSA-2023:7034 |
| Red Hat Enterprise Linux 8 | python39:3.9-8090020230922213827.7484f1d1 | Fixed | RHSA-2023:7034 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | python-pip-0:9.0.3-22.1.el8_6 | Fixed | RHSA-2024:0374 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | python3-0:3.6.8-47.el8_6.4 | Fixed | RHSA-2024:0430 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | python-pip-0:9.0.3-22.1.el8_8 | Fixed | RHSA-2024:0587 |
| Red Hat Enterprise Linux 9 | python-pip-0:21.2.3-7.el9 | Fixed | RHSA-2023:6694 |
| Red Hat Enterprise Linux 9 | python-pip-0:21.2.3-7.el9 | Fixed | RHSA-2023:6694 |
| Red Hat Enterprise Linux 9 | python3.11-0:3.11.5-1.el9_3 | Fixed | RHSA-2023:6494 |
| Red Hat Enterprise Linux 9 | python3.11-pip-0:22.3.1-4.el9 | Fixed | RHSA-2023:6324 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.18-1.el9_3 | Fixed | RHSA-2023:6659 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.18-1.el9_3 | Fixed | RHSA-2023:6659 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-0:3.8.18-2.el7 | Fixed | RHSA-2023:6793 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-pip-0:19.3.1-4.el7 | Fixed | RHSA-2023:6793 |
| Red Hat Enterprise Linux 6 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python2 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Product Security has rated this issue as having a Moderate security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification. Versions of `python36:3.6/python36` as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main `python3` component, which provides the actual interpreter of the Python programming language.
Red Hat mitigation
Do not extract archives from untrusted sources with the Python tarfile module. Users of the module should add sanity checks when calling the tarfile.extract or tarfile.extractall functions.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jan 17, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (53 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 27.10% (0.27095) | 97.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 27.10% (0.27095) | 97.79th | v5 (v2026.06.15) |
| May 11, 2026 | 90.19% (0.90194) | 99.60th | v4 (v2025.03.14) |
| Apr 29, 2026 | 89.03% (0.89029) | 99.53th | v4 (v2025.03.14) |
| Mar 4, 2026 | 90.58% (0.90582) | 99.60th | v4 (v2025.03.14) |
| Mar 1, 2026 | 87.87% (0.87871) | 99.47th | v4 (v2025.03.14) |
| Feb 4, 2026 | 90.58% (0.90582) | 99.60th | v4 (v2025.03.14) |
| Feb 1, 2026 | 87.87% (0.87871) | 99.47th | v4 (v2025.03.14) |
| Jan 26, 2026 | 90.58% (0.90582) | 99.59th | v4 (v2025.03.14) |
| Jan 4, 2026 | 88.93% (0.88929) | 99.50th | v4 (v2025.03.14) |
| Jan 1, 2026 | 84.89% (0.84887) | 99.32th | v4 (v2025.03.14) |
| Dec 4, 2025 | 89.29% (0.89294) | 99.51th | v4 (v2025.03.14) |
| Dec 1, 2025 | 85.74% (0.85742) | 99.34th | v4 (v2025.03.14) |
| Nov 4, 2025 | 88.55% (0.88553) | 99.47th | v4 (v2025.03.14) |
| Nov 1, 2025 | 86.43% (0.86427) | 99.38th | v4 (v2025.03.14) |
| Oct 4, 2025 | 88.55% (0.88553) | 99.47th | v4 (v2025.03.14) |
| Oct 1, 2025 | 86.43% (0.86427) | 99.38th | v4 (v2025.03.14) |
| Sep 23, 2025 | 89.07% (0.89070) | 99.51th | v4 (v2025.03.14) |
| Sep 22, 2025 | 91.34% (0.91339) | 99.65th | v4 (v2025.03.14) |
| Sep 5, 2025 | 92.35% (0.92351) | 99.72th | v4 (v2025.03.14) |
| Sep 1, 2025 | 90.66% (0.90664) | 99.61th | v4 (v2025.03.14) |
| Aug 4, 2025 | 92.99% (0.92993) | 99.77th | v4 (v2025.03.14) |
| Aug 1, 2025 | 91.80% (0.91802) | 99.68th | v4 (v2025.03.14) |
| Jul 4, 2025 | 93.02% (0.93020) | 99.77th | v4 (v2025.03.14) |
| Jul 1, 2025 | 91.74% (0.91742) | 99.67th | v4 (v2025.03.14) |
| Jun 4, 2025 | 93.02% (0.93020) | 99.77th | v4 (v2025.03.14) |
| Jun 1, 2025 | 91.74% (0.91742) | 99.67th | v4 (v2025.03.14) |
| May 4, 2025 | 93.02% (0.93020) | 99.77th | v4 (v2025.03.14) |
| May 1, 2025 | 91.74% (0.91742) | 99.67th | v4 (v2025.03.14) |
| Mar 30, 2025 | 93.02% (0.93020) | 99.78th | v4 (v2025.03.14) |
| Mar 29, 2025 | 86.94% (0.86943) | 99.30th | v4 (v2025.03.14) |
| Mar 28, 2025 | 93.02% (0.93020) | 99.78th | v4 (v2025.03.14) |
| Mar 27, 2025 | 86.94% (0.86943) | 99.38th | v4 (v2025.03.14) |
| Mar 20, 2025 | 92.66% (0.92662) | 99.76th | v4 (v2025.03.14) |
| Mar 19, 2025 | 86.94% (0.86943) | 99.40th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.66% (0.92662) | 99.75th | v4 (v2025.03.14) |
| Dec 17, 2024 | 6.50% (0.06504) | 93.66th | v3 (v2023.03.01) |
| Aug 8, 2024 | 9.34% (0.09341) | 94.79th | v3 (v2023.03.01) |
| Jul 1, 2024 | 2.69% (0.02687) | 90.53th | v3 (v2023.03.01) |
| May 24, 2024 | 2.47% (0.02467) | 90.04th | v3 (v2023.03.01) |
| Apr 16, 2024 | 2.43% (0.02431) | 89.81th | v3 (v2023.03.01) |
| Mar 23, 2024 | 2.10% (0.02102) | 88.90th | v3 (v2023.03.01) |
| Mar 16, 2024 | 2.09% (0.02093) | 88.85th | v3 (v2023.03.01) |
| Mar 9, 2024 | 1.34% (0.01338) | 85.74th | v3 (v2023.03.01) |
| Sep 17, 2023 | 0.95% (0.00947) | 81.31th | v3 (v2023.03.01) |
| Aug 3, 2023 | 1.03% (0.01028) | 81.91th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.52% (0.00517) | 73.57th | v3 (v2023.03.01) |
| May 8, 2023 | 0.51% (0.00509) | 73.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.48% (0.00477) | 71.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.19% (0.09187) | 94.21th | v2 (v2022.01.01) |
| Sep 22, 2022 | 9.19% (0.09187) | 93.96th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.21% (0.01213) | 64.21th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.21% (0.01213) | 40.54th | v2 (v2022.01.01) |
References (15)
- http://mail.python.org/pipermail/python-dev/2007-August/074290.html mailing-listMailing ListVendor Advisory
- http://mail.python.org/pipermail/python-dev/2007-August/074292.html mailing-listExploitMailing List
- http://secunia.com/advisories/26623 third-party-advisoryBroken Link
- http://www.vupen.com/english/advisories/2007/3022 vdb-entryBroken Link
- https://access.redhat.com/security/cve/CVE-2007-4559 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=263261 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/
- https://nvd.nist.gov/vuln/detail/CVE-2007-4559
- https://security.gentoo.org/glsa/202309-06 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2007-4559
Change history (0)
No recorded changes yet.