Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh55-9p6r-h46f

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

EPSS

Процентиль: 81%
0.01674
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 18 лет назад

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

redhat
почти 18 лет назад

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

nvd
почти 18 лет назад

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

debian
почти 18 лет назад

Directory traversal vulnerability in extract.c in star before 1.5a84 a ...

oracle-oval
почти 18 лет назад

ELSA-2007-0873: Moderate: star security update (MODERATE)

EPSS

Процентиль: 81%
0.01674
Низкий

Дефекты

CWE-22