CVE-2002-1216: Medium severity GNU tar vulnerability
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Other sources
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2002-1216?
CVE-2002-1216 has a high severity rating due to the potential for arbitrary file overwriting by remote attackers.
How do I fix CVE-2002-1216?
To fix CVE-2002-1216, upgrade GNU tar to version 1.13.25 or later to restore the necessary security checks.
Which versions of GNU tar are affected by CVE-2002-1216?
GNU tar versions 1.13.19 and below are affected by CVE-2002-1216.
What type of attack does CVE-2002-1216 involve?
CVE-2002-1216 involves a symlink attack allowing remote attackers to overwrite arbitrary files.
Are there any workarounds for CVE-2002-1216?
The main workaround for CVE-2002-1216 is to disable the use of symlinks in operations that use GNU tar until an upgrade can be applied.