<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:04:51.349440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:6324</id>
    <title>ALSA-2023:6324 — Moderate: python3.11-pip security update</title>
    <updated>2026-10-02T13:04:51.395209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3.11-pip, AlmaLinux:9: python3.11-pip-wheel</p>
<p>pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either "Pip Installs Packages" or "Pip Installs Python".</p>
<p>Security Fix(es):</p>
<p>* python: tarfile module directory traversal (CVE-2007-4559)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:6324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05975</id>
    <title>bdu:2022-05975</title>
    <updated>2026-10-02T13:04:51.395301+00:00</updated>
    <content>bdu:2022-05975</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2007-4559</id>
    <title>Withdrawn: BELL-CVE-2007-4559 — CVE-2007-4559 does not affect BellSoft software</title>
    <updated>2026-10-02T13:04:51.395319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-python-2007-4559</id>
    <title>BIT-python-2007-4559</title>
    <updated>2026-10-02T13:04:51.395335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: python</p>
<p>Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-python-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</id>
    <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T13:04:51.395356+00:00</updated>
    <content>certfr-2024-avi-0385</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2023:0425</id>
    <title>ESSA-2023:0425 — Product split of RHSA-2023:7034 python39:3.9 module</title>
    <updated>2026-10-02T13:04:51.395371+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Product split of RHSA-2023:7034 python39:3.9 module</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2023:0425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-211040</id>
    <title>EUVD-2026-211040</title>
    <updated>2026-10-02T13:04:51.395390+00:00</updated>
    <content>EUVD-2026-211040</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-211040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2007-4559</id>
    <title>fkie_cve-2007-4559</title>
    <updated>2026-10-02T13:04:51.395401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gw9q-c7gh-j9vm</id>
    <title>GHSA-gw9q-c7gh-j9vm</title>
    <updated>2026-10-02T13:04:51.395421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gw9q-c7gh-j9vm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2007-4559</id>
    <title>gsd-2007-4559</title>
    <updated>2026-10-02T13:04:51.395436+00:00</updated>
    <content>gsd-2007-4559</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2007-4559</id>
    <title>msrc_CVE-2007-4559 — Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allow…</title>
    <updated>2026-10-02T13:04:51.395446+00:00</updated>
    <content>msrc_CVE-2007-4559</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1518</id>
    <title>OESA-2023-1518 — python3 security update</title>
    <updated>2026-10-02T13:04:51.395462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces. This package Provides python version 3.</p>
<p>Security Fix(es):</p>
<p>Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.(CVE-2007-4559)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:6793</id>
    <title>RHSA-2023:6793 — Red Hat Security Advisory: rh-python38-python security update</title>
    <updated>2026-10-02T13:04:51.395485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:6793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2473-1</id>
    <title>SUSE-SU-2023:2473-1 — Security update for python36</title>
    <updated>2026-10-02T13:04:51.395513+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python36</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2473-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2007-4559</id>
    <title>UBUNTU-CVE-2007-4559</title>
    <updated>2026-10-02T13:04:51.395535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:20.04:LTS: python3.8, Ubuntu:22.04:LTS: python2.7, Ubuntu:22.04:LTS: python3.10 and 1 more</p>
<p>Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2007-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1501</id>
    <title>WID-SEC-W-2022-1501 — Python: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T13:04:51.395569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1501"/>
  </entry>
</feed>
