First published: Thu Aug 30 2007(Updated: )
Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4134 is classified as a medium severity vulnerability due to its ability to allow overwriting of arbitrary files.
To fix CVE-2007-4134, update to a version of star that is later than 1.5a84, which resolves the directory traversal issue.
CVE-2007-4134 affects versions of star prior to 1.5a84, specifically on systems like Fedora 7.
CVE-2007-4134 enables user-assisted remote attackers to exploit the vulnerability through crafted TAR archives.
The nature of CVE-2007-4134 is a directory traversal vulnerability that allows manipulation of file paths through symlink exploitation.