Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6321

Опубликовано: 27 окт. 2016
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact, a future update may address this flaw. This issue did not affect the versions of star as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Меры по смягчению последствий

Use the "star" utility provided by the "star" package to process archives from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5starNot affected
Red Hat Enterprise Linux 5tarWill not fix
Red Hat Enterprise Linux 6starNot affected
Red Hat Enterprise Linux 6tarWill not fix
Red Hat Enterprise Linux 7starNot affected
Red Hat Enterprise Linux 7tarWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1318562tar: Bypassing the extract path name

EPSS

Процентиль: 96%
0.15155
Средний

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
nvd
больше 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
debian
больше 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in ...

suse-cvrf
больше 9 лет назад

Security update for tar

suse-cvrf
больше 9 лет назад

Security update for tar

EPSS

Процентиль: 96%
0.15155
Средний

5.1 Medium

CVSS2