Description
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
CVSS vector
AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9Complexity: Low
Confidentiality: None
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
2GHSAGHSA-p23r-j983-4557: Directory traversal vulnerability in GNU tar 1↗2022-05-03 ▶ CVEListCVE-2001-1267: Directory traversal vulnerability in GNU tar 1↗2004-09-01 ▶ 📋Vendor Advisories
3Red Hatpython: tarfile module directory traversal↗2007-08-24 ▶ 💬Community
4BugzillaCVE-2001-1267 security flaw↗2018-08-16 ▶ BugzillaCVE-2002-0399 security flaw↗2018-08-16 ▶ BugzillaCVE-2007-4829 perl-Archive-Tar directory traversal flaws↗2007-09-18 ▶ BugzillaCVE-2007-4559 python: tarfile module directory traversal↗2007-08-29 ▶