Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6321

Опубликовано: 27 окт. 2016
Источник: redhat
CVSS2: 5.1

Описание

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact, a future update may address this flaw. This issue did not affect the versions of star as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Меры по смягчению последствий

Use the "star" utility provided by the "star" package to process archives from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5starNot affected
Red Hat Enterprise Linux 5tarWill not fix
Red Hat Enterprise Linux 6starNot affected
Red Hat Enterprise Linux 6tarWill not fix
Red Hat Enterprise Linux 7starNot affected
Red Hat Enterprise Linux 7tarWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1318562tar: Bypassing the extract path name

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
nvd
около 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
debian
около 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in ...

suse-cvrf
около 9 лет назад

Security update for tar

suse-cvrf
около 9 лет назад

Security update for tar

5.1 Medium

CVSS2