Lucene search

K
redhatcveRedhat.comRH:CVE-2016-6321
HistoryOct 27, 2016 - 7:47 a.m.

CVE-2016-6321

2016-10-2707:47:17
redhat.com
access.redhat.com
18

EPSS

0.005

Percentile

76.1%

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

Mitigation

Use the "star" utility provided by the "star" package to process archives from untrusted sources.