PT-2007-5966 · Perl+1 · Archive Tar+1

Tomas Hoger

·

Published

2007-11-02

·

Updated

2018-08-08

·

CVE-2007-4829

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Archive::Tar Perl module versions 1.36 and earlier
Description: The issue allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Recommendations: For Archive::Tar Perl module versions 1.36 and earlier, update to a version later than 1.36 to resolve the issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4829
RHSA-2010:0505
RHSA-2010_0505

Affected Products

Archive Tar
Red Hat