First published: Mon Aug 13 2007(Updated: )
Directory traversal vulnerability was discovered in GNU tar. Vulnerability can be exploited by specially crafted tar archive to overwrite arbitrary file writable by user running tar. Problem occurs in contains_dot_dot function, which does not properly check names of directory symlinks. Acknowledgements: Red Hat would like to thank Dmitry V. Levin for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu tar |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-251921 is considered high due to the potential for arbitrary file overwriting.
To fix REDHAT-BUG-251921, update to the latest patched version of GNU tar that addresses the directory traversal vulnerability.
The systems affected by REDHAT-BUG-251921 include those running vulnerable versions of GNU tar.
Yes, REDHAT-BUG-251921 can be exploited remotely through the distribution of specially crafted tar archives.
Exploiting REDHAT-BUG-251921 may allow an attacker to overwrite arbitrary files, which could lead to unauthorized access or system compromise.