FlawAtlas
Search the atlas
CVE-2007-4559 Critical

Directory path traversal in extract() and extractall() tarfile functions via '..' (dot dot) sequences

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

Exploit probability 27.1%
Published August 28, 2007
Required by Not available
Last source change February 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Bitnami python-min
Bitnami python
Unknown Unknown

330 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-python-min-2007-4559

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

View original source
Open Source Vulnerabilities BIT-python-2007-4559

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

View original source
Open Source Vulnerabilities PSF-2007-2

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

View original source

05 / REFERENCES

Further evidence