The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
CVSS
No CVSS.
References
Configurations
No configuration.
History
13 Mar 2026, 19:53
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
12 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-434 CWE-20 CWE-74 |
12 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-12 18:16
Updated : 2026-03-13 19:53
NVD link : CVE-2025-13462
Mitre link : CVE-2025-13462
CVE.ORG link : CVE-2025-13462
JSON object : View
Products Affected
No product.
