CVE-2005-2541: Critical severity GNU tar vulnerability
Published Aug 10, 2005
·Updated
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Affected Software
1 affected component
GNU tar=1.15.1
Event History
Aug 10, 2005
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2541?
CVE-2005-2541 has a medium severity as it may allow local users or remote attackers to gain privileges.
2
How do I fix CVE-2005-2541?
To fix CVE-2005-2541, upgrade to a version of tar that includes proper warnings for setuid and setgid files.
3
What software versions are affected by CVE-2005-2541?
CVE-2005-2541 specifically affects GNU tar version 1.15.1.
4
Can CVE-2005-2541 be exploited remotely?
Yes, CVE-2005-2541 can be exploited by remote attackers if they can convince a user to extract a malicious tar file.
5
What are the potential impacts of CVE-2005-2541?
The potential impacts of CVE-2005-2541 include privilege escalation for local users and potential compromise of system integrity.