Security News > 2022 > September > Python tarfile vulnerability affects 350,000 open-source projects (CVE-2007-4559)

Python tarfile vulnerability affects 350,000 open-source projects (CVE-2007-4559)
2022-09-22 08:20

Trellix Advanced Research Center published its research into CVE-2007-4559, a vulnerability estimated to be present in over 350,000 open-source projects and prevalent in closed-source projects.

The vulnerability exists in the Python tarfile module which is a default module in any project using Python and is found extensively in frameworks created by Netflix, AWS, Intel, Facebook, Google, and applications used for machine learning, automation and docker containerization.

The vulnerability can be exploited by uploading a malicious file generated with two or three lines of simple code and allows attackers arbitrary code execution, or control of a target device.

"When we talk about supply chain threats, we typically refer to cyber-attacks like the SolarWinds incident, however building on top of weak code-foundations can have an equally severe impact," said Christiaan Beek, Head of Adversarial & Vulnerability Research, Trellix.

Open-source developer tools, like Python, are necessary to advance computing and innovation, and protection from known vulnerabilities requires industry collaboration.

Researchers are working to push code via GitHub pull request to protect open-source projects from the vulnerability.


News URL

https://www.helpnetsecurity.com/2022/09/22/cve-2007-4559/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2007-08-28 CVE-2007-4559 Path Traversal vulnerability in Python
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a ..
0.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Python 24 2 52 74 31 159