Loading
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Use CWE-22, Python vendor hub and Python product page to widen CVE-2007-4559 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-6232, CVE-2024-7592 and CVE-2023-41105 for nearby disclosures in the same product family.