CVE-2001-1267

CWE-22Path Traversal10 documents5 sources
Severity
2.1LOW
EPSS
0.1%
top 68.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 12
Latest updateMay 3

Description

Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

NVDgnu/tar1.13.19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p23r-j983-4557: Directory traversal vulnerability in GNU tar 12022-05-03
CVEList
CVE-2001-1267: Directory traversal vulnerability in GNU tar 12004-09-01

📋Vendor Advisories

3
Red Hat
python: tarfile module directory traversal2007-08-24
Red Hat
security flaw2002-09-30
Red Hat
security flaw2001-07-12

💬Community

4
Bugzilla
CVE-2001-1267 security flaw2018-08-16
Bugzilla
CVE-2002-0399 security flaw2018-08-16
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws2007-09-18
Bugzilla
CVE-2007-4559 python: tarfile module directory traversal2007-08-29