在 CPython 3.13 及更早版本中, 模块的数据过滤器和 tar 解包过滤器易受包含指向符号链接的硬链接的恶意构造归档文件的影响。此类归档文件可能导致解包过程修改目标目录外文件的权限或修改时间,或在解压后的目录树中暴露该文件的内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Python Software Foundation | CPython | < 3.14.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Python Software Foundation | CPython | 0 ~ 3.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet