Lucene search

K
mageiaGentoo FoundationMGASA-2014-0090
HistoryFeb 21, 2014 - 10:18 p.m.

Updated libtar package fixes security vulnerability

2014-02-2122:18:54
Gentoo Foundation
advisories.mageia.org
19

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.003

Percentile

71.6%

A directory traversal attack was reported against libtar, a C library for manipulating tar archives. The application does not validate the filenames inside the tar archive, allowing to extract files in arbitrary path. An attacker can craft a tar file to override files beyond the tar_extract_glob and tar_extract_all prefix parameter (CVE-2013-4420).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchlibtar< 1.2.18-2.2libtar-1.2.18-2.2.mga3
Mageia4noarchlibtar< 1.2.20-2.1libtar-1.2.20-2.1.mga4

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.003

Percentile

71.6%