Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43w6-q9mv-9cwf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

Ссылки

EPSS

Процентиль: 92%
0.08719
Низкий

Связанные уязвимости

ubuntu
почти 18 лет назад

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

redhat
почти 18 лет назад

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

nvd
почти 18 лет назад

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

debian
почти 18 лет назад

Directory traversal vulnerability in the contains_dot_dot function in ...

oracle-oval
почти 18 лет назад

ELSA-2007-0860: Moderate: tar security update (MODERATE)

EPSS

Процентиль: 92%
0.08719
Низкий