First published: Thu Aug 23 2007(Updated: )
The GNU tar program saves many files together in one archive and can<br>restore individual files (or all of the files) from that archive. <br>A path traversal flaw was discovered in the way GNU tar extracted archives.<br>A malicious user could create a tar archive that could write to arbitrary<br>files to which the user running GNU tar had write access. (CVE-2007-4131)<br>Red Hat would like to thank Dmitry V. Levin for reporting this issue.<br>Users of tar should upgrade to this updated package, which contains a<br>replacement backported patch to correct this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tar | <1.15.1-23.0.1.el5 | 1.15.1-23.0.1.el5 |
redhat/tar | <1.15.1-23.0.1.el5 | 1.15.1-23.0.1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2007:0860 is classified as moderate.
To fix RHSA-2007:0860, update the tar package to version 1.15.1-23.0.1.el5 or later.
RHSA-2007:0860 is a path traversal vulnerability in the GNU tar program.
RHSA-2007:0860 affects versions of tar before 1.15.1-23.0.1.el5.
No specific workarounds are available for RHSA-2007:0860; the recommended action is to apply the security update.