Echo: python3.11: security update to 3.11.2-6+deb12u3

high Tenable Cloud Security Plugin ID 460931

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination
directory, and the modification of some file metadata. You are affected by this vulnerability if using the
tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the
filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation
https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that
for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you
are relying on this new default behavior then your usage is also affected. Note that none of these
vulnerabilities significantly affect the installation of source distributions which are tar archives as
source distributions already allow arbitrary code execution during the build process. However when
evaluating source distributions it's important to avoid installing source distributions with suspicious
links. (CVE-2025-4330)

Solution

Update the python3.11 library and its related packages to version 3.11.2-6+deb12u3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-4330

Plugin Details

Severity: High

ID: 460931

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.29

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2025-4330

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/15/2025

Reference Information

CVE: CVE-2025-4330