CVE-2016-6321
Severity
7.5HIGH
EPSS
11.1%
top 6.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Latest updateMay 13
Description
Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-4qpm-74c6-fg44: Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1↗2022-05-13
OSV▶
CVE-2016-6321: Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1↗2016-12-09
CVEList▶
CVE-2016-6321: Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1↗2016-12-09