CVE-2005-2541
published 2005-08-10CVE-2005-2541: Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.99%
89.4th percentile
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tar | — | — |
| gnu | tar | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwpx-f983-qg79: Tar 1
ghsa_unreviewed·2022-05-01
CVE-2005-2541 [HIGH] GHSA-vwpx-f983-qg79: Tar 1
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
OSV
CVE-2005-2541: Tar 1
osv·2005-08-10·CVSS 10.0
CVE-2005-2541 [CRITICAL] CVE-2005-2541: Tar 1
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Red Hat
tar: does not properly warn the user when extracting setuid or setgid files
vendor_redhat·2005-08-04·CVSS 10.0
CVE-2005-2541 [CRITICAL] tar: does not properly warn the user when extracting setuid or setgid files
tar: does not properly warn the user when extracting setuid or setgid files
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
A flaw was found in tar utility that can allow the root user to extract files with preserved setuid and setgid permissions without any warning. This behavior can lead to the creation of malicious setuid executables owned by root from a crafted tar file, posing significant security risks.
Statement: Currently, there are no plans to change tar behaviour to strip setuid and setgid bits when extracting archives.
This vulnerability is considered moderate rather than important because the exploitation scenario requires specific conditions: the `tar` extraction must be p
Debian
CVE-2005-2541: tar - Tar 1.15.1 does not properly warn the user when extracting setuid or setgid file...
vendor_debian·2005·CVSS 10.0
CVE-2005-2541 [CRITICAL] CVE-2005-2541: tar - Tar 1.15.1 does not properly warn the user when extracting setuid or setgid file...
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=112327628230258&w=2https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3Ehttp://marc.info/?l=bugtraq&m=112327628230258&w=2https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
2005-08-10
Published