PT-2007-1070 · Star+1 · Star+1
Publicado
2007-08-30
·
Atualizado
2018-10-15
·
CVE-2007-4134
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
star versions prior to 1.5a84
Description:
The issue allows remote attackers to exploit a directory traversal vulnerability in the extract.c component of the star package. This can be achieved by using certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive, potentially leading to the overwriting of arbitrary files. The exploitation of this issue may result in the disruption of confidentiality, integrity, and availability of protected information.
Recommendations:
For versions prior to 1.5a84, update to version 1.5a84 or later to resolve the issue. As a temporary workaround, consider restricting the use of the extract.c component in the star package until a patch is available. Avoid using the star package to extract TAR archives from untrusted sources until the issue is resolved.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Star