← Back

CVE-2025-13462

nvd nist
Published: Mar 12, 2026Modified: Jun 11, 2026

JSON object

Loading...
2.0
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

Affected (9)

Products: Python: Python
1 product
Python
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 3.13.13
From 3.14.0 to 3.14.4
Version 3.15.0 alpha1
Version 3.15.0 alpha2
Version 3.15.0 alpha3
Version 3.15.0 alpha4
Version 3.15.0 alpha5
Version 3.15.0 alpha6
Version 3.15.0 alpha7

Timeline

No history available yet.