Lucene search

K
osvGoogleOSV:DSA-1438-1
HistoryDec 28, 2007 - 12:00 a.m.

tar

2007-12-2800:00:00
Google
osv.dev
14

0.02 Low

EPSS

Percentile

88.9%

Several vulnerabilities have been discovered in GNU Tar. The Common
Vulnerabilities and Exposures project identifies the following problems:

A directory traversal vulnerability enables attackers using
specially crafted archives to extract contents outside the
directory tree created by tar.

A stack-based buffer overflow in the file name checking code may
lead to arbitrary code execution when processing maliciously
crafted archives.

For the old stable distribution (sarge), these problems have been
fixed in version 1.14-2.4.

For the stable distribution (etch), these problems have been fixed in
version 1.16-2etch1.

For the unstable distribution (sid), these problems have been fixed in
version 1.18-2.

We recommend that you upgrade your tar package.

CPENameOperatorVersion
tareq1.14-2
tareq1.14-2.1
tareq1.14-2.2
tareq1.14-2.3