PT-2001-1074 · Red Hat+1 · Red Hat+1

Publicado

2001-07-12

·

Atualizado

2024-06-15

·

CVE-2001-1267

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GNU tar versions 1.13.19 and earlier Red Hat Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the tar package, which can lead to the integrity of protected information being compromised. Exploitation of these vulnerabilities can be performed remotely. A directory traversal vulnerability in GNU tar allows local users to overwrite arbitrary files during archive extraction via a tar file with filenames containing .. (dot dot).
Recommendations For GNU tar versions 1.13.19 and earlier, consider restricting access to the archive extraction functionality until a patch is available. For Red Hat Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08351
CVE-2001-1267
OPENSUSE-SU-2024:11422-1

Produtos afetados

Gnu Tar
Red Hat