cbcvebase.
CVE-2002-1216
published 2002-10-28

CVE-2002-1216: GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification…

PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.57%
72.8th percentile
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiantar< tar 1.16-2 (bookworm)tar 1.16-2 (bookworm)
debiantar< tar 1.13.25 (bookworm)tar 1.13.25 (bookworm)
gnutar<= 1.13.25
gnutar
gnutar
gnutar
gnutar>= 0 < 1.13.251.13.25
gnutar>= 0 < 1.16-21.16-2
gnutar>= 0 < 1.13.251.13.25
gnutar>= 0 < 1.16-21.16-2
gnutar>= 0 < 1.13.251.13.25
gnutar>= 0 < 1.16-21.16-2
gnutar>= 0 < 1.13.251.13.25
gnutar>= 0 < 1.16-21.16-2

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.