CVE-2005-1918: Path Traversal
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1918?
CVE-2005-1918 has a high severity rating due to its potential for file overwrite vulnerabilities.
How do I fix CVE-2005-1918?
To fix CVE-2005-1918, users should update to a patched version of GNU tar or Red Hat Enterprise Linux that addresses this vulnerability.
What systems are affected by CVE-2005-1918?
CVE-2005-1918 affects specific versions of GNU tar and Red Hat Enterprise Linux 2.1 and 3.0.
What is the exploitation method for CVE-2005-1918?
CVE-2005-1918 can be exploited using crafted tar files that contain directory traversal sequences, such as '/../'.
Is there a workaround for CVE-2005-1918?
A temporary workaround for CVE-2005-1918 is to avoid using GNU tar in untrusted environments until a patch can be applied.