security advisorycriticaldebian
It was discovered that insecure path handling in the Python interface to the Internet Archive/archive.org could result in overwriting a user's files. For the oldstable distribution (bookworm), this problem has been fixed in version 3.3.0-2~deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6035-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 23, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-internetarchive CVE ID : CVE-2025-58438 It was discovered that insecure path handling in the Python interface to the Internet Archive/archive.org could result in overwriting a user's files. For the oldstable distribution (bookworm), this problem has been fixed in version 3.3.0-2~deb12u1. For the stable distribution (trixie), this problem has been fixed in version 5.4.0-2~deb13u1. We recommend that you upgrade your python-internetarchive packages. For the detailed security status of python-internetarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-internetarchive Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Insecure path handling in Python Internet Archive fixed in Debian updates to prevent file overwriting.. python internetarchive, debian advisory, insecure paths, security updates. . Severity: Critical. LinuxSecurity.com Team
Oct 23, 2025
•Critical
Debian