PT-2001-1074 · Red Hat+1 · Red Hat+1
Publicado
2001-07-12
·
Atualizado
2024-06-15
·
CVE-2001-1267
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GNU tar versions 1.13.19 and earlier
Red Hat Linux (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the tar package, which can lead to the integrity of protected information being compromised. Exploitation of these vulnerabilities can be performed remotely. A directory traversal vulnerability in GNU tar allows local users to overwrite arbitrary files during archive extraction via a tar file with filenames containing
.. (dot dot).Recommendations
For GNU tar versions 1.13.19 and earlier, consider restricting access to the archive extraction functionality until a patch is available.
For Red Hat Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnu Tar
Red Hat