<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:03:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6324 — Moderate: python3.11-pip security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.11-pip, AlmaLinux:9: python3.11-pip-wheel&lt;/p&gt;
&lt;p&gt;pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either &amp;#34;Pip Installs Packages&amp;#34; or &amp;#34;Pip Installs Python&amp;#34;.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: tarfile module directory traversal (CVE-2007-4559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.11-pip, AlmaLinux:9: python3.11-pip-wheel&lt;/p&gt;
&lt;p&gt;pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either &amp;#34;Pip Installs Packages&amp;#34; or &amp;#34;Pip Installs Python&amp;#34;.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: tarfile module directory traversal (CVE-2007-4559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6324</guid>
    </item>
    <item>
      <title>bdu:2022-05975</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05975</link>
      <description>bdu:2022-05975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05975</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2007-4559 — CVE-2007-4559 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2007-4559</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2007-4559</guid>
    </item>
    <item>
      <title>BIT-python-2007-4559</title>
      <link>https://cve.radiocsirt.org/vuln/bit-python-2007-4559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: python&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: python&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-python-2007-4559</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</link>
      <description>certfr-2024-avi-0385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</guid>
    </item>
    <item>
      <title>ESSA-2023:0425 — Product split of RHSA-2023:7034 python39:3.9 module</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2023:0425</link>
      <description>&lt;p&gt;Product split of RHSA-2023:7034 python39:3.9 module&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Product split of RHSA-2023:7034 python39:3.9 module&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2023:0425</guid>
    </item>
    <item>
      <title>EUVD-2026-211040</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211040</link>
      <description>EUVD-2026-211040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211040</guid>
    </item>
    <item>
      <title>fkie_cve-2007-4559</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2007-4559</link>
      <description>&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2007-4559</guid>
    </item>
    <item>
      <title>GHSA-gw9q-c7gh-j9vm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gw9q-c7gh-j9vm</link>
      <description>&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gw9q-c7gh-j9vm</guid>
    </item>
    <item>
      <title>gsd-2007-4559</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2007-4559</link>
      <description>gsd-2007-4559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2007-4559</guid>
    </item>
    <item>
      <title>msrc_CVE-2007-4559 — Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allow…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2007-4559</link>
      <description>msrc_CVE-2007-4559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2007-4559</guid>
    </item>
    <item>
      <title>OESA-2023-1518 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces. This package Provides python version 3.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.(CVE-2007-4559)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces. This package Provides python version 3.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.(CVE-2007-4559)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1518</guid>
    </item>
    <item>
      <title>RHSA-2023:6793 — Red Hat Security Advisory: rh-python38-python security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:6793</link>
      <description>&lt;p&gt;python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:6793</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2473-1 — Security update for python36</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2473-1</link>
      <description>&lt;p&gt;Security update for python36&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python36&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2473-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2007-4559</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2007-4559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:20.04:LTS: python3.8, Ubuntu:22.04:LTS: python2.7, Ubuntu:22.04:LTS: python3.10 and 1 more&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:20.04:LTS: python3.8, Ubuntu:22.04:LTS: python2.7, Ubuntu:22.04:LTS: python3.10 and 1 more&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2007-4559</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1501 — Python: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1501</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1501</guid>
    </item>
  </channel>
</rss>
