{"id":135918,"date":"2025-06-06T03:05:07","date_gmt":"2025-06-06T01:05:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs"},"modified":"2025-06-06T03:05:07","modified_gmt":"2025-06-06T01:05:07","slug":"uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs","title":{"rendered":"Vulnerabilit\u00e0 nel modulo Python TarFile, che consente la scrittura in qualsiasi parte del filesystem","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel modulo tarfile fornito con Python, che offre funzioni per la lettura e la scrittura di archivi tar, sono state identificate cinque vulnerabilit\u00e0, una delle quali ha ricevuto un livello di gravit\u00e0 critico. Le vulnerabilit\u00e0 sono state corrette nelle versioni Python 3.13.4 e 3.12.11. La vulnerabilit\u00e0 pi\u00f9 pericolosa (CVE-2025-4517) consente di scrivere file in qualsiasi parte del filesystem durante l'estrazione di un archivio appositamente creato. Nello script di sistema che utilizza tarfile e viene eseguito con i diritti di root (ad esempio, in utilit\u00e0 per la gestione dei pacchetti e nei contenitori isolati), la vulnerabilit\u00e0 pu\u00f2 essere sfruttata per ottenere privilegi elevati o per fuoriuscire dal contenitore isolato.    <\/p>\n<p>La vulnerabilit\u00e0 riguarda i progetti in cui il modulo tarfile viene utilizzato per estrarre archivi tar non attendibili, utilizzando la funzione TarFile.extractall() o TarFile.extract() con il parametro \"filter=\" impostato su \"data\" o \"tar\". La vulnerabilit\u00e0 \u00e8 causata da una gestione errata della sequenza \"..\" nel nome del collegamento. Il problema riguarda le versioni di Python a partire dalla 3.12. La modalit\u00e0 'filter='data'' \u00e8 impostata di default nel ramo Python 3.14, attualmente in sviluppo (il rilascio \u00e8 previsto per l'autunno).     <\/p>\n<p>Altre vulnerabilit\u00e0 in TarFile:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2025-4330 \u2014 possibilit\u00e0 di bypassare il filtro dei dati estratti, che potrebbe portare all'estrazione di un collegamento simbolico che punta al di fuori della directory di base in cui avviene l'estrazione.\n<li class=\"l\"> CVE-2025-4138 \u2014 possibilit\u00e0 di creare collegamenti simbolici arbitrari al di fuori della directory di base durante l'estrazione di archivi con il parametro 'filter='data''.\n<li class=\"l\"> CVE-2024-12718 \u2014 possibilit\u00e0 di modificare i metadati (ad esempio, il tempo di modifica) dei file al di fuori della directory di base durante l'estrazione di archivi con il parametro 'filter='data'' o le autorizzazioni di accesso (chmod) durante l'estrazione di archivi con il parametro 'filter='tar''.\n<li class=\"l\"> CVE-2025-4435 \u2014 se durante l'estrazione di un archivio il parametro TarFile.errorlevel \u00e8 impostato su 0, contrariamente alla documentazione, gli elementi dell'archivio che rientrano nel filtro specificato venivano estratti, anzich\u00e9 ignorati.    <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63365\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0448\u0442\u0430\u0442\u043d\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443 Python \u043c\u043e\u0434\u0443\u043b\u0435 tarfile, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 Python 3.13.4 \u0438 3.12.11. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-4517) \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0430\u0440\u0445\u0438\u0432\u0430 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0432 \u043b\u044e\u0431\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b. \u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u043a\u0440\u0438\u043f\u0442\u0430\u0445, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-135918","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0448\u0442\u0430\u0442\u043d\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443 Python \u043c\u043e\u0434\u0443\u043b\u0435 tarfile, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Python-\u043c\u043e\u0434\u0443\u043b\u0435 TarFile, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0448\u0442\u0430\u0442\u043d\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443 Python \u043c\u043e\u0434\u0443\u043b\u0435 tarfile, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-06-06T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-06-06T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 nel modulo Python TarFile, che consente di scrivere in qualsiasi parte del filesystem | ProHoster","description":"Nel modulo tarfile fornito con Python, che offre funzioni per la lettura e la scrittura di archivi tar, sono state identificate cinque vulnerabilit\u00e0, una delle quali ha ricevuto un livello di gravit\u00e0 critico.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Python-\u043c\u043e\u0434\u0443\u043b\u0435 TarFile, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u0437\u0430\u043f\u0438\u0441\u044c \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421 | ProHoster","og:description":"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0448\u0442\u0430\u0442\u043d\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443 Python \u043c\u043e\u0434\u0443\u043b\u0435 tarfile, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-python-module-tarfile-dopuskayushhaya-zapis-v-lyubye-chasti-fs","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-06-06T01:05:07+00:00","article:modified_time":"2025-06-06T01:05:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"135918","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 13:11:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 13:11:21","updated":"2026-01-23 13:11:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/135918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=135918"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/135918\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=135918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=135918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=135918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}