« Volver al listado

CVE-2025-13462

Estado: AnalizadaBaja (2)—

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-13462",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-13462",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-12T19:09:23.808172Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@python.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 2,
          "Automatable": "NOT_DEFINED",
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "repo": "https://github.com/python/cpython",
          "vendor": "Python Software Foundation",
          "modules": [
            "tarfile"
          ],
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.10.21",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.16",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.14",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0",
              "lessThan": "3.13.13",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.14.0",
              "lessThan": "3.14.4",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.15.0a1",
              "lessThan": "3.15.0a8",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-12T18:16:21.397",
  "references": [
    {
      "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/141707",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/143934",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "cna@python.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-74"
        },
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations."
    },
    {
      "lang": "es",
      "value": "El módulo 'tarfile' seguiría aplicando la normalización de bloques AREGTYPE (\\x00) a DIRTYPE, incluso al procesar un miembro de múltiples bloques como GNUTYPE_LONGNAME o GNUTYPE_LONGLINK. Esto podría resultar en un archivo tar manipulado siendo malinterpretado por el módulo tarfile en comparación con otras implementaciones."
    }
  ],
  "lastModified": "2026-08-13T01:16:50.980",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74460139-CF2A-457B-82B4-7B655FB576B1",
              "versionEndExcluding": "3.13.13"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA3B34C3-1E02-4674-8370-0DD4D24DBE58",
              "versionEndExcluding": "3.14.4",
              "versionStartIncluding": "3.14.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3327507-0B1D-4F28-A983-D07A2C8A7696"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8AF17F1-A27F-4C98-BA5A-B4319710E8D1"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24CF56B0-2F4E-42A2-B655-F493AA0A4815"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7184ABBA-B100-489E-B5C1-1C9EEC0546CA"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6D4181B-3E1B-499B-AAB1-50868A6A6AD3"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A52F6DD2-717D-4E8C-8DB7-00890BC1ABAE"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C46C55C-801E-4F86-B669-8E6A12B4AB6F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@python.org"
}