First published: Tue Dec 10 2013(Updated: )
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libtar | 1.2.20-8 1.2.20-8.1 | |
CentOS Libtar | <=1.2.20 | |
CentOS Libtar | =1.2.11 | |
CentOS Libtar | =1.2.13 | |
CentOS Libtar | =1.2.14 | |
CentOS Libtar | =1.2.15 | |
CentOS Libtar | =1.2.16 | |
CentOS Libtar | =1.2.17 | |
CentOS Libtar | =1.2.18 | |
CentOS Libtar | =1.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4420 is classified as a high severity vulnerability due to its ability to allow remote attackers to overwrite arbitrary files.
To fix CVE-2013-4420, upgrade the libtar package to version 1.2.20-9 or later.
CVE-2013-4420 affects libtar versions up to and including 1.2.20.
Exploiting CVE-2013-4420 can lead to unauthorized file access and overwriting of critical system files.
Yes, CVE-2013-4420 is a remote vulnerability that can be exploited by attackers through crafted tar files.