CVE-2001-1267
published 2001-07-12CVE-2001-1267: Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose…
PriorityP413low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
1.07%
61.3th percentile
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | tar | <= 1.13.19 | — |
| gnu | tar | — | — |
| python | python | < 3.6.16 | 3.6.16 |
| python | python | >= 3.10.0 < 3.10.12 | 3.10.12 |
| python | python | >= 3.11.0 < 3.11.4 | 3.11.4 |
| python | python | >= 3.7.0 < 3.8.17 | 3.8.17 |
| python | python | >= 3.9.0 < 3.9.17 | 3.9.17 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python: tarfile module directory traversal
vendor_redhat·2007-08-24·CVSS 2.1
CVE-2007-4559 [LOW] CWE-22 python: tarfile module directory traversal
python: tarfile module directory traversal
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
A flaw was found in the Python tarfile module. Extracting a crafted TAR archive with the tarfile.extract or tarfile.extractall functions could lead to a directory traversal vulnerability, resulting in overwrite of arbitrary files.
Statement: The Red Hat Product Security has rated this issue as having a Moderate security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classif
Red Hat
security flaw
vendor_redhat·2002-09-30·CVSS 2.1
CVE-2002-0399 [LOW] security flaw
security flaw
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
Red Hat
security flaw
vendor_redhat·2001-07-12·CVSS 2.1
CVE-2001-1267 [LOW] security flaw
security flaw
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
GHSA
GHSA-p23r-j983-4557: Directory traversal vulnerability in GNU tar 1
ghsa_unreviewed·2022-05-03
CVE-2001-1267 [LOW] GHSA-p23r-j983-4557: Directory traversal vulnerability in GNU tar 1
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
GHSA
GHSA-gw9q-c7gh-j9vm: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker
ghsa_unreviewed·2022-05-01·CVSS 2.1
CVE-2007-4559 [LOW] CWE-22 GHSA-gw9q-c7gh-j9vm: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
GHSA
GHSA-c6fq-h555-8326: Directory traversal vulnerability in GNU tar 1
ghsa_unreviewed·2022-04-30·CVSS 2.1
CVE-2002-0399 [LOW] GHSA-c6fq-h555-8326: Directory traversal vulnerability in GNU tar 1
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
OSV
CVE-2007-4559: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker
osv·2007-08-28·CVSS 2.1
CVE-2007-4559 [LOW] CVE-2007-4559: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2001-1267 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2001-1267 [LOW] CVE-2001-1267 security flaw
CVE-2001-1267 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
Bugzilla
CVE-2002-0399 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2002-0399 [LOW] CVE-2002-0399 security flaw
CVE-2002-0399 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws
bugzilla·2007-09-18·CVSS 2.1
CVE-2007-4829 [LOW] CVE-2007-4829 perl-Archive-Tar directory traversal flaws
CVE-2007-4829 perl-Archive-Tar directory traversal flaws
Directory traversal vulnerability in Archive::Tar perl module allows
user-assisted remote attackers to overwrite arbitrary files writable by user
running application using this module via an absolute path or a .. (dot dot)
sequence in filenames in a TAR archive.
Similar issues were reported and fixed for GNU tar during past several years,
e.g.: CVE-2001-1267, CVE-2002-0399, CVE-2002-1216 and CVE-2007-4131.
This issue is important when this module is used to extract tar archives from
untrusted sources. However, some of such applications either implement
workarounds / own checks (sa-update in spamassassin) or dropped module support
at all (amavisd-new).
Discussion:
Similar issue was reported for Python's tarfile module, see #26326
Bugzilla
CVE-2007-4559 python: tarfile module directory traversal
bugzilla·2007-08-29·CVSS 2.1
CVE-2007-4559 [LOW] CVE-2007-4559 python: tarfile module directory traversal
CVE-2007-4559 python: tarfile module directory traversal
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4559
to the following vulnerability:
Directory traversal vulnerability in the (1) extract and (2) extractall
functions in the tarfile module in Python allows user-assisted remote attackers
to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR
archive, a related issue to CVE-2001-1267.
References:
Issue and additional attack vectors were discussed in following thread on
python-dev mailinglist:
http://mail.python.org/pipermail/python-dev/2007-August/074290.html
Upstream bug tracking possible fixes for the issue:
http://bugs.python.org/issue1044
Discussion:
Ok, so they seem confused about whether they wanted to fix anything or just
def
ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gzhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538http://online.securityfocus.com/advisories/4514http://online.securityfocus.com/archive/1/196445http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1http://www.iss.net/security_center/static/10224.phphttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:066http://www.redhat.com/support/errata/RHSA-2002-096.htmlhttp://www.redhat.com/support/errata/RHSA-2002-138.htmlhttp://www.redhat.com/support/errata/RHSA-2003-218.htmlhttp://www.securityfocus.com/bid/3024ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gzhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538http://online.securityfocus.com/advisories/4514http://online.securityfocus.com/archive/1/196445http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1http://www.iss.net/security_center/static/10224.phphttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:066http://www.redhat.com/support/errata/RHSA-2002-096.htmlhttp://www.redhat.com/support/errata/RHSA-2002-138.htmlhttp://www.redhat.com/support/errata/RHSA-2003-218.htmlhttp://www.securityfocus.com/bid/3024
2001-07-12
Published