/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-h6qq-2p9f-rrpx

Published

Last updated

https://images.chainguard.dev/security/CGA-h6qq-2p9f-rrpx
Package

python-3.11

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2007-4559
  • GHSA-gw9q-c7gh-j9vm

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2007-4559

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

Upon further investigation, we have determined that this is not a security issue in the Python package itself. It's still possible to misuse the Python standard library, such as by supplying untrusted data to the tar extraction functions, in which case a vulnerability should be identified in the caller code.

Status

Affected

Impact

Users should upgrade to version 3.11.4-r0 or later and set the filter parameter to 'data' when calling TarFile.extract and TarFile.extractall methods. For more information, see https://peps.python.org/pep-0706/.

Status

Not affected

Justification

Vulnerable code not present

Impact

The upstream issue has been closed, deeming this to be expected behavior, not a security issue. See https://bugs.python.org/issue1044.


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing