CVE-2002-1216

10 documents7 sources
Severity
5.0MEDIUM
EPSS
0.7%
top 28.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 30

Description

GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantar< 1.13.25+3
NVDgnu/tar1.13.25+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-29pg-f8vr-x2wh: GNU tar 12022-04-30
OSV
CVE-2002-1216: GNU tar 12002-10-28
CVEList
CVE-2002-1216: GNU tar 12002-10-21

📋Vendor Advisories

3
Red Hat
security flaw2006-11-21
Red Hat
security flaw2002-09-28
Debian
CVE-2002-1216: tar - GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to ove...2002

💬Community

3
Bugzilla
CVE-2002-1216 security flaw2018-08-16
Bugzilla
CVE-2006-6097 security flaw2018-08-16
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws2007-09-18