CVE-2013-4420
published 2014-02-20CVE-2013-4420: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers…
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
3.28%
87.0th percentile
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libtar | < libtar 1.2.20-2 (bookworm) | libtar 1.2.20-2 (bookworm) |
| feep | libtar | <= 1.2.20 | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | — | — |
| feep | libtar | >= 0 < 1.2.20-2 | 1.2.20-2 |
| feep | libtar | >= 0 < 1.2.20-2 | 1.2.20-2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | libtar-1.2.20-11.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | libtar-1.2.20-11.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | libtar-1.2.20-8.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | libtar-1.2.20-8.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | libtar-1.2.20-8.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | libtar-1.2.20-8.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | libtar-debuginfo-1.2.20-8.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | libtar-debuginfo-1.2.20-8.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | libtar-debuginfo-1.2.20-8.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_msrc5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2013-4420: Mariner: Mariner
secalert@redhat
vendor_msrc·2024-06-11·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420: Mariner: Mariner
secalert@redhat
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
libtar: missing validation of file names
vendor_redhat·2013-10-01·CVSS 5.8
CVE-2013-4420 [MEDIUM] libtar: missing validation of file names
libtar: missing validation of file names
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Package: libtar (Red Hat Enterprise Linux 6) - Will not fix
Package: libtar (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2013-4420: libtar - Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2)...
vendor_debian·2013·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420: libtar - Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2)...
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Scope: local
bookworm: resolved (fixed in 1.2.20-2)
bullseye: resolved (fixed in 1.2.20-2)
GHSA
GHSA-35h8-7h6c-x54q: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1
ghsa_unreviewed·2022-05-17
CVE-2013-4420 [MEDIUM] CWE-22 GHSA-35h8-7h6c-x54q: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
OSV
CVE-2013-4420: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1
osv·2014-02-20·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4420 libtar: missing validation of file names
bugzilla·2013-10-11·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420 libtar: missing validation of file names
CVE-2013-4420 libtar: missing validation of file names
libtar was found to have a flaw where it does not validate the file names stored inside a tar file, which could possibly lead to a file extraction outside the prefix path.
The functions "tar_extract_glob" and "tar_extract_all" accept a path prefix on where to extract files to, but libtar doesn't validate the file names inside the tar file. For example: consider a file name "../../etc/passwd". If extract_all is called with prefix "/home/USER/", libtar would try to overwrite "/etc/passwd".
There is a workaround where a user could validate all filenames inside tar archive before calling tar_extract_*, but it seems that most of the users don't do that, so it's better that libtar should itself validate the file names.
References:
http:/
Bugzilla
CVE-2013-4420 libtar: missing validation of file names [fedora-all]
bugzilla·2013-10-11·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420 libtar: missing validation of file names [fedora-all]
CVE-2013-4420 libtar: missing validation of file names [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multi
Bugzilla
CVE-2013-4420 libtar: missing validation of file names [epel-5]
bugzilla·2013-10-11·CVSS 5.8
CVE-2013-4420 [MEDIUM] CVE-2013-4420 libtar: missing validation of file names [epel-5]
CVE-2013-4420 libtar: missing validation of file names [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for libtar: see
http://www.debian.org/security/2014/dsa-2863https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731860https://lists.feep.net:8080/pipermail/libtar/2014-February/000403.htmlhttp://www.debian.org/security/2014/dsa-2863https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731860https://lists.feep.net:8080/pipermail/libtar/2014-February/000403.html
2014-02-20
Published