Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Patool < 4.0.5 Path Traversal via safe_extract() Function
Vulnerability Description
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
wummel patool 路径遍历漏洞
Vulnerability Description
wummel patool是wummel组织的一款命令行归档工具。 wummel patool 4.0.5之前版本存在路径遍历漏洞,该漏洞源于safe_extract()函数中的路径遍历问题,允许攻击者通过特制的归档成员路径绕过包含检查,并写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A