CVE-2007-4134
published 2007-08-30CVE-2007-4134: Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.01%
85.9th percentile
Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fedora | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
star directory traversal vulnerability
vendor_redhat·2007-08-21·CVSS 6.8
CVE-2007-4134 [MEDIUM] star directory traversal vulnerability
star directory traversal vulnerability
Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
GHSA
GHSA-vh55-9p6r-h46f: Directory traversal vulnerability in extract
ghsa_unreviewed·2022-05-03
CVE-2007-4134 [MEDIUM] CWE-22 GHSA-vh55-9p6r-h46f: Directory traversal vulnerability in extract
Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4134 star directory traversal vulnerability [F7]
bugzilla·2007-08-24·CVSS 6.8
CVE-2007-4134 [MEDIUM] CVE-2007-4134 star directory traversal vulnerability [F7]
CVE-2007-4134 star directory traversal vulnerability [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
star-1.5a84-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-4134 star directory traversal vulnerability [FC6]
bugzilla·2007-08-24·CVSS 6.8
CVE-2007-4134 [MEDIUM] CVE-2007-4134 star directory traversal vulnerability [FC6]
CVE-2007-4134 star directory traversal vulnerability [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2007-4134 star directory traversal vulnerability
bugzilla·2007-08-22·CVSS 6.8
CVE-2007-4134 [MEDIUM] CVE-2007-4134 star directory traversal vulnerability
CVE-2007-4134 star directory traversal vulnerability
A directory traversal vulnerability has been discovered in star. Directory
traversal check implemented in has_dotdot() function in extract.c does not
correctly handle paths which have '/' character doubled, e.g. 'dir//..//..//'.
More info:
https://bugs.gentoo.org/show_bug.cgi?id=189690
Acknowledgements:
Red Hat would like to thank Robert Buchholz for reporting this issue.
Discussion:
Created attachment 162052
Patch propsed by upstream.
---
Another CVE name - CVE-2007-4558 - was assigned by Mitre to this issue on
2007-08-27.
---
CVE-2007-4558 rejected as duplicate of CVE-2007-4134 on 2007-08-30.
---
Fixed in all affected products:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0873.html
Fedora:
updated to
ftp://ftp.berlios.de/pub/star/alpha/AN-1.5a84ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.aschttp://secunia.com/advisories/26626http://secunia.com/advisories/26672http://secunia.com/advisories/26673http://secunia.com/advisories/26857http://secunia.com/advisories/27318http://secunia.com/advisories/27544http://securitytracker.com/id?1018646http://support.avaya.com/elmodocs2/security/ASA-2007-414.htmhttp://www.gentoo.org/security/en/glsa/glsa-200710-23.xmlhttp://www.redhat.com/archives/fedora-package-announce/2007-August/msg00425.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0873.htmlhttp://www.securityfocus.com/archive/1/478797/100/200/threadedhttps://bugs.gentoo.org/show_bug.cgi?id=189690https://issues.rpath.com/browse/RPL-1669https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11098ftp://ftp.berlios.de/pub/star/alpha/AN-1.5a84ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.aschttp://secunia.com/advisories/26626http://secunia.com/advisories/26672http://secunia.com/advisories/26673http://secunia.com/advisories/26857http://secunia.com/advisories/27318http://secunia.com/advisories/27544http://securitytracker.com/id?1018646http://support.avaya.com/elmodocs2/security/ASA-2007-414.htmhttp://www.gentoo.org/security/en/glsa/glsa-200710-23.xmlhttp://www.redhat.com/archives/fedora-package-announce/2007-August/msg00425.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0873.htmlhttp://www.securityfocus.com/archive/1/478797/100/200/threadedhttps://bugs.gentoo.org/show_bug.cgi?id=189690https://issues.rpath.com/browse/RPL-1669https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11098
2007-08-30
Published