CVE-2013-4420Path Traversal in Libtar

CWE-22Path Traversal9 documents7 sources
Severity
5.8MEDIUMNVD
EPSS
0.4%
top 40.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateJun 11

Description

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

CVSS vector

AV:N/AC:M/C:N/I:P/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages23 packages

🔴Vulnerability Details

2
GHSA
GHSA-35h8-7h6c-x54q: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 12022-05-17
OSV
CVE-2013-4420: Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 12014-02-20

📋Vendor Advisories

3
Microsoft
CVE-2013-4420: Mariner: Mariner secalert@redhat2024-06-11
Red Hat
libtar: missing validation of file names2013-10-01
Debian
CVE-2013-4420: libtar - Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2)...2013

💬Community

3
Bugzilla
CVE-2013-4420 libtar: missing validation of file names2013-10-11
Bugzilla
CVE-2013-4420 libtar: missing validation of file names [fedora-all]2013-10-11
Bugzilla
CVE-2013-4420 libtar: missing validation of file names [epel-5]2013-10-11
CVE-2013-4420 — Path Traversal in Debian Libtar | cvebase