CVE-2025-32799
Linux Fedora vulnerability analysis and mitigation

Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives containing entries with directory traversal sequences to write files outside the intended extraction directory. This could lead to arbitrary file overwrites, privilege escalation, or code execution if sensitive locations are targeted. This issue has been patched in version 25.4.0.


SourceNVD

Related Linux Fedora vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69194HIGH8.8
  • Linux DebianLinux Debian
  • wget2-libs
NoYesJan 09, 2026
CVE-2025-69195HIGH7.6
  • Linux DebianLinux Debian
  • wget2-libs-debuginfo
NoYesJan 09, 2026
CVE-2025-56225HIGH7.5
  • Linux DebianLinux Debian
  • musescoreicon-fonts
NoYesJan 09, 2026
CVE-2025-67858HIGH7
  • Linux DebianLinux Debian
  • foomuuri_exporter
NoYesJan 08, 2026
CVE-2025-67603MEDIUM5.1
  • Linux DebianLinux Debian
  • foomuuri
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management