Another fresh #Python #tarfile #vulnerability
Python TarFile.extractall(..., filter='tar') arbitrary file chmod
Another fresh #Python #tarfile #vulnerability
Python TarFile.extractall(..., filter='tar') arbitrary file chmod
A couple other fun bugs 🐛
#Python - #Tarfile Realpath Overflow #Vulnerability
https://github.com/google/security-research/security/advisories/GHSA-hgqp-3mmf-7h8f
#Python #Tar Filter Bypass #Vulnerability
https://github.com/google/security-research/security/advisories/GHSA-7fj8-pjw2-r9vh
That's not good, at all 🤔😑💩
"15-Year-Old Unpatched Python Vulnerability Potentially Affects Over 350,000 Projects" (CVE-2007-4559)
https://thehackernews.com/2022/09/15-year-old-unpatched-python.html
#devops #cybersec #cybersecurity #python #vulnerability #tarfile #security #bug #code #programming #programmer
Trellix Advanced Research Center stumbled across a vulnerability in Python’s tarfile module. As we dug into the issue, we realized this was in fact CVE-2007-4559. The vulnerability is a path traversal attack in the extract and extractall functions in the tarfile module that allow an attacker to overwrite arbitrary files by adding the “..” sequence to filenames in a TAR archive. Over the course of our research into the impact of this vulnerability we discovered that hundreds of thousands of repositories were vulnerable to this vulnerability. While the vulnerability was originally only marked as a 6.8, we were able to confirm that in most cases an attacker can gain code execution from the file write.
@obsolete29
Then there are #tarfile versions of some #softwares, which *can* be updated in-software, it depends on individual developers.
Unless folks check #PGPSignatures of #software that they get online though, we don't recommend #downloading software manually.
Hashtags for future searchers: #appImages #appImage #legit #legitSoftware #appUpdates #softwareUpdate #packageManager #updates #aptGet #flatPaks #PPA #PPAs #authenticity
@realsimon