Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-6321

Опубликовано: 09 дек. 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

РелизСтатусПримечание
devel

not-affected

1.29b-1.1
esm-infra-legacy/trusty

released

1.27.1-1ubuntu0.1
esm-infra/xenial

released

1.28-2.1ubuntu0.1
precise

released

1.26-4ubuntu1.1
precise/esm

not-affected

1.26-4ubuntu1.1
trusty

released

1.27.1-1ubuntu0.1
trusty/esm

released

1.27.1-1ubuntu0.1
upstream

released

1.29b-1.1
vivid/stable-phone-overlay

ignored

end of life
vivid/ubuntu-core

ignored

end of life

Показывать по

EPSS

Процентиль: 93%
0.11143
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
больше 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
nvd
около 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS3: 7.5
debian
около 9 лет назад

Directory traversal vulnerability in the safer_name_suffix function in ...

suse-cvrf
около 9 лет назад

Security update for tar

suse-cvrf
около 9 лет назад

Security update for tar

EPSS

Процентиль: 93%
0.11143
Средний

5 Medium

CVSS2

7.5 High

CVSS3