漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Patool < 4.0.5 Path Traversal via safe_extract() Function
Vulnerability Description
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
wummel patool 路径遍历漏洞
Vulnerability Description
wummel patool是wummel组织的一款命令行归档工具。 wummel patool 4.0.5之前版本存在路径遍历漏洞,该漏洞源于safe_extract()函数中的路径遍历问题,允许攻击者通过特制的归档成员路径绕过包含检查,并写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A