CVE-2006-0931: Path Traversal
Published Feb 28, 2006
·Updated
Directory traversal vulnerability in PEAR::ArchiveTar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.
Affected Software
4 affected componentsFixes available
composer/pear/archive_tar>=1.2<1.3.2
1.3.2
PEAR Pear Archive Tar<=1.2
PEAR Pear Archive Tar<=1.3.0
PEAR Pear Archive Tar<=1.3.1
Event History
Feb 28, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·06:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2006-0931?
CVE-2006-0931 is rated as a critical vulnerability due to its ability to allow remote attackers to overwrite arbitrary files.
2
How do I fix CVE-2006-0931?
To fix CVE-2006-0931, upgrade PEAR::Archive_Tar to version 1.3.2 or later.
3
Which versions are affected by CVE-2006-0931?
CVE-2006-0931 affects PEAR::Archive_Tar versions 1.2 and 1.3.1 or earlier.
4
What types of attacks are possible with CVE-2006-0931?
CVE-2006-0931 allows directory traversal attacks that can lead to file creation and overwriting.
5
Is CVE-2006-0931 a local or remote vulnerability?
CVE-2006-0931 is considered a remote vulnerability, allowing attackers to exploit it without local access.