First published: Sat Sep 28 2002(Updated: )
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu tar | =1.13.19 | |
Ubuntu tar | <=1.13.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1216 has a high severity rating due to the potential for arbitrary file overwriting by remote attackers.
To fix CVE-2002-1216, upgrade GNU tar to version 1.13.25 or later to restore the necessary security checks.
GNU tar versions 1.13.19 and below are affected by CVE-2002-1216.
CVE-2002-1216 involves a symlink attack allowing remote attackers to overwrite arbitrary files.
The main workaround for CVE-2002-1216 is to disable the use of symlinks in operations that use GNU tar until an upgrade can be applied.