First published: Tue Dec 10 2013(Updated: )
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libtar | 1.2.20-8 1.2.20-8.1 | |
feep libtar | <=1.2.20 | |
feep libtar | =1.2.11 | |
feep libtar | =1.2.13 | |
feep libtar | =1.2.14 | |
feep libtar | =1.2.15 | |
feep libtar | =1.2.16 | |
feep libtar | =1.2.17 | |
feep libtar | =1.2.18 | |
feep libtar | =1.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.