THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-13462 (LOW 3.3) — The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to ot

[NVD] CVE-2025-13462 (LOW 3.3) — The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to ot

lownvdPublished 2026-03-12

CVE-2025-13462 CVSS: 3.3 LOW Published: 2026-03-12T18:16:21.397

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13462