CVE-2007-4829
published 2007-11-02CVE-2007-4829: Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.32%
90.2th percentile
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | perl | < perl 5.10.0-19 (bookworm) | perl 5.10.0-19 (bookworm) |
| perl | perl | >= 0 < 5.10.0-19 | 5.10.0-19 |
| perl | perl | >= 0 < 5.10.0-19 | 5.10.0-19 |
| perl | perl | >= 0 < 5.10.0-19 | 5.10.0-19 |
| perl | perl | >= 0 < 5.10.0-19 | 5.10.0-19 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl regression
vendor_ubuntu·2009-01-15·CVSS 6.8
[MEDIUM] Perl regression
Title: Perl regression
Summary: Perl regression
USN-700-1 fixed vulnerabilities in Perl. Due to problems with the Ubuntu
8.04 build, some Perl .ph files were missing from the resulting update.
This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2008-12-24·CVSS 6.8
CVE-2007-4829 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl vulnerabilities
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could crash the application, leading to a denial
of service. Ubuntu 8.10 was not affected by this issue. (CVE-2008-1927)
A race condition was discovered in the File::Path Perl module's rmtree
function. If a local attacker successfully r
Red Hat
perl-Archive-Tar directory traversal flaws
vendor_redhat·2007-08-24·CVSS 6.8
CVE-2007-4829 [MEDIUM] perl-Archive-Tar directory traversal flaws
perl-Archive-Tar directory traversal flaws
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-4829
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
https://access.redhat.com/security/updates/classification/
Debian
CVE-2007-4829: perl - Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earli...
vendor_debian·2007·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829: perl - Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earli...
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Scope: local
bookworm: resolved (fixed in 5.10.0-19)
bullseye: resolved (fixed in 5.10.0-19)
forky: resolved (fixed in 5.10.0-19)
sid: resolved (fixed in 5.10.0-19)
trixie: resolved (fixed in 5.10.0-19)
GHSA
GHSA-rwhc-g7xj-h37q: Directory traversal vulnerability in the Archive::Tar Perl module 1
ghsa_unreviewed·2022-05-01
CVE-2007-4829 [MEDIUM] CWE-22 GHSA-rwhc-g7xj-h37q: Directory traversal vulnerability in the Archive::Tar Perl module 1
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
OSV
CVE-2007-4829: Directory traversal vulnerability in the Archive::Tar Perl module 1
osv·2007-11-02·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829: Directory traversal vulnerability in the Archive::Tar Perl module 1
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
bugzilla·2018-06-14·CVSS 6.8
CVE-2018-10860 [MEDIUM] CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
Archive::Zip does not protect against symlinks or '..' path traversals. Attacks similar to CVE-2007-4829 or CVE-2018-12015 also affect Archive::Zip.
Discussion:
Archive::Zip has never been part of upstream Perl release:
$ corelist Archive::Zip
Data for 2018-04-14
Archive::Zip was not in CORE (or so I think)
It's an independent project .
---
Note: summary edited for clarification.
---
Acknowledgments:
Name: Doran Moppert (Red Hat)
---
Created perl-Archive-Zip tracking bugs for this issue:
Affects: fedora-all [bug 1596132]
---
Upstream fix:
https://github.com/redhotpenguin/perl-Archive-Zip/commit/95e1df86327
---
perl-Archive-Zip-1.59-6.fc27 has been pushed to the Fedora 27 stable repository. If problems st
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [Fdevel]
bugzilla·2007-11-02·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829 perl-Archive-Tar directory traversal flaws [Fdevel]
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Based on the date this bug was created, it appears to have been reported
during the development of Fedora 8. In order to refocus our efforts as
a project we are changing the version of this bug to '8'.
If this bug still exists in rawhide, please change the version back to
rawhide.
(If you're unable to change the bug's version, add a comment to the bug
and someone will change it for you.)
Thanks for your help and we apologize for the interruption.
The process we're following is outlined here:
http://fedoraproject.org/wiki/BugZappers/F9CleanUp
We will be following the proces
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F8]
bugzilla·2007-11-02·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F8]
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '8'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version prior to Fedora 8's end of life.
Bug Reporter: Tha
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [FC6]
bugzilla·2007-10-02·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829 perl-Archive-Tar directory traversal flaws [FC6]
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora apologizes that these issues have not been resolved yet. We're
sorry it's taken so long for your bug to be properly triaged and acted
on. We appreciate the time you took to report this issue and want to
make sure no important bugs slip through the cracks.
If you're currently running a version of Fedora Core between 1 and 6,
please note that Fedora no longer maintains these releases. We strongly
encourage you to upgrade to a current Fedora release. In order to
refocus our efforts as a project we are flagging all of the open bugs
for releases which are no longer maintained and
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F7]
bugzilla·2007-10-02·CVSS 6.8
CVE-2007-4829 [MEDIUM] CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F7]
CVE-2007-4829 perl-Archive-Tar directory traversal flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a reminder that Fedora 7 is nearing the end of life. Approximately 30 (thirty) days from now Fedora will stop maintaining and issuing updates for Fedora 7. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as WONTFIX if it remains open with a Fedora 'version' of '7'.
Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, simply change the 'version' to a later Fedora version prior to Fedora 7's end of life.
Bug Reporter: Tha
Bugzilla
CVE-2007-4829 perl-Archive-Tar directory traversal flaws
bugzilla·2007-09-18·CVSS 2.1
CVE-2007-4829 [LOW] CVE-2007-4829 perl-Archive-Tar directory traversal flaws
CVE-2007-4829 perl-Archive-Tar directory traversal flaws
Directory traversal vulnerability in Archive::Tar perl module allows
user-assisted remote attackers to overwrite arbitrary files writable by user
running application using this module via an absolute path or a .. (dot dot)
sequence in filenames in a TAR archive.
Similar issues were reported and fixed for GNU tar during past several years,
e.g.: CVE-2001-1267, CVE-2002-0399, CVE-2002-1216 and CVE-2007-4131.
This issue is important when this module is used to extract tar archives from
untrusted sources. However, some of such applications either implement
workarounds / own checks (sa-update in spamassassin) or dropped module support
at all (amavisd-new).
Discussion:
Similar issue was reported for Python's tarfile module, see #26326
http://osvdb.org/40410http://rt.cpan.org/Public/Bug/Display.html?id=29517http://rt.cpan.org/Public/Bug/Display.html?id=30380http://secunia.com/advisories/27539http://secunia.com/advisories/33116http://secunia.com/advisories/33314http://www.gentoo.org/security/en/glsa/glsa-200812-10.xmlhttp://www.securityfocus.com/bid/26355http://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2http://www.vupen.com/english/advisories/2007/3755https://bugzilla.redhat.com/show_bug.cgi?id=295021https://exchange.xforce.ibmcloud.com/vulnerabilities/38285https://issues.rpath.com/browse/RPL-1716https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11658http://osvdb.org/40410http://rt.cpan.org/Public/Bug/Display.html?id=29517http://rt.cpan.org/Public/Bug/Display.html?id=30380http://secunia.com/advisories/27539http://secunia.com/advisories/33116http://secunia.com/advisories/33314http://www.gentoo.org/security/en/glsa/glsa-200812-10.xmlhttp://www.securityfocus.com/bid/26355http://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2http://www.vupen.com/english/advisories/2007/3755https://bugzilla.redhat.com/show_bug.cgi?id=295021https://exchange.xforce.ibmcloud.com/vulnerabilities/38285https://issues.rpath.com/browse/RPL-1716https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11658
2007-11-02
Published