PT-2005-3435 · Gnu+1 · Tar+1
Imran Ghory
·
Published
2005-08-10
·
Updated
2026-04-29
·
CVE-2005-2541
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tar version 1.15.1
Description
The issue is related to the extraction of setuid or setgid files, where the software does not properly warn the user. This may allow local users or remote attackers to gain privileges.
Recommendations
For Tar version 1.15.1, consider updating to a newer version that addresses this issue, as the current version does not properly handle the extraction of setuid or setgid files, potentially leading to privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Tar