PT-2001-1074 · Red Hat+1 · Red Hat+1

Published

2001-07-12

·

Updated

2024-06-15

·

CVE-2001-1267

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GNU tar versions 1.13.19 and earlier Red Hat Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the tar package, which can lead to the integrity of protected information being compromised. Exploitation of these vulnerabilities can be performed remotely. A directory traversal vulnerability in GNU tar allows local users to overwrite arbitrary files during archive extraction via a tar file with filenames containing .. (dot dot).
Recommendations For GNU tar versions 1.13.19 and earlier, consider restricting access to the archive extraction functionality until a patch is available. For Red Hat Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08351
CVE-2001-1267
OPENSUSE-SU-2024:11422-1

Affected Products

Gnu Tar
Red Hat