PT-2005-3435 · Gnu+1 · Tar+1

Imran Ghory

·

Publicado

2005-08-10

·

Atualizado

2026-04-29

·

CVE-2005-2541

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tar version 1.15.1
Description The issue is related to the extraction of setuid or setgid files, where the software does not properly warn the user. This may allow local users or remote attackers to gain privileges.
Recommendations For Tar version 1.15.1, consider updating to a newer version that addresses this issue, as the current version does not properly handle the extraction of setuid or setgid files, potentially leading to privilege escalation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2541
ECHO-A597-344D-59BE

Produtos afetados

Debian
Tar