cbcvebase.
CVE-2005-1918
published 2005-12-31

CVE-2005-1918: The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that…

PriorityP417low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.86%
85.2th percentile
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".

Affected

10 ranges
VendorProductVersion rangeFixed in
debiantar< tar 1.14-2.2 (bookworm)tar 1.14-2.2 (bookworm)
gnutar
gnutar>= 0 < 1.14-2.21.14-2.2
gnutar>= 0 < 1.14-2.21.14-2.2
gnutar>= 0 < 1.14-2.21.14-2.2
gnutar>= 0 < 1.14-2.21.14-2.2
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatlinux_advanced_workstation

CVSS provenance

nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.