CVE-2016-6321: Path Traversal
Directory traversal vulnerability in the safernamesuffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the filename parameter, aka POINTYFEATHER.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6321?
CVE-2016-6321 is considered a medium severity vulnerability that allows attackers to bypass protections and write to arbitrary files.
How do I fix CVE-2016-6321?
To fix CVE-2016-6321, update GNU tar to version 1.30 or later, which addresses this directory traversal vulnerability.
Which versions of GNU tar are affected by CVE-2016-6321?
CVE-2016-6321 affects GNU tar versions from 1.14 to 1.29 inclusive.
What type of vulnerability is CVE-2016-6321?
CVE-2016-6321 is a directory traversal vulnerability that exploits improper sanitization of file names.
Can CVE-2016-6321 be exploited remotely?
Yes, CVE-2016-6321 can be exploited by remote attackers to compromise file security.