First published: Fri Aug 24 2007(Updated: )
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Archive | <=1.36 | |
Ubuntu | =6.06 | |
Ubuntu | =7.10 | |
Ubuntu | =8.04 | |
Ubuntu | =8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4829 is a directory traversal vulnerability in the Archive::Tar Perl module that allows attackers to overwrite arbitrary files through specially crafted TAR archives.
CVE-2007-4829 is considered a critical vulnerability due to its potential to compromise system integrity by allowing file overwriting.
To fix CVE-2007-4829, you should upgrade the Archive::Tar module to version 1.37 or later.
CVE-2007-4829 affects Archive::Tar Perl module versions 1.36 and earlier, as well as various versions of Ubuntu Linux that utilize this module.
Yes, CVE-2007-4829 can be exploited by remote attackers but requires user assistance to process a malicious TAR archive.