PT-2001-1074 · Red Hat+1 · Red Hat+1
Published
2001-07-12
·
Updated
2024-06-15
·
CVE-2001-1267
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GNU tar versions 1.13.19 and earlier
Red Hat Linux (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the tar package, which can lead to the integrity of protected information being compromised. Exploitation of these vulnerabilities can be performed remotely. A directory traversal vulnerability in GNU tar allows local users to overwrite arbitrary files during archive extraction via a tar file with filenames containing
.. (dot dot).Recommendations
For GNU tar versions 1.13.19 and earlier, consider restricting access to the archive extraction functionality until a patch is available.
For Red Hat Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnu Tar
Red Hat