Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

github логотип

GHSA-f93m-9mq4-2fjj

около 1 года назад

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 4.1
EPSS: Низкий
ubuntu логотип

CVE-2025-45582

около 1 года назад

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 4.1
EPSS: Низкий
redhat логотип

CVE-2025-45582

около 1 года назад

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2025-45582

около 1 года назад

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh

CVSS3: 4.1
EPSS: Низкий
msrc логотип

CVE-2025-45582

11 месяцев назад

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh

EPSS: Низкий
debian логотип

CVE-2025-45582

около 1 года назад

GNU Tar through 1.35 allows file overwrite via directory traversal in ...

CVSS3: 4.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20472-1

4 месяца назад

Security update for tar

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2615-1

около 1 месяца назад

Security update for tar

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1177-1

4 месяца назад

Security update for tar

EPSS: Низкий
rocky логотип

RLSA-2026:0067

7 месяцев назад

Moderate: tar security update

EPSS: Низкий
rocky логотип

RLSA-2026:0002

7 месяцев назад

Moderate: tar security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0067

7 месяцев назад

ELSA-2026-0067: tar security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0002

7 месяцев назад

ELSA-2026-0002: tar security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2026-00339

около 1 года назад

Уязвимость архиватора GNU Tar, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти существующие ограничения безопасности и получить доступ на перезапись файлов

CVSS3: 4.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21070-1

около 1 месяца назад

Security update for tar

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f93m-9mq4-2fjj

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 4.1
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 4.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in...

CVSS3: 5.6
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh

CVSS3: 4.1
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh

0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in ...

CVSS3: 4.1
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20472-1

Security update for tar

0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2615-1

Security update for tar

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1177-1

Security update for tar

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:0067

Moderate: tar security update

0%
Низкий
7 месяцев назад
rocky логотип
RLSA-2026:0002

Moderate: tar security update

0%
Низкий
7 месяцев назад
oracle-oval логотип
ELSA-2026-0067

ELSA-2026-0067: tar security update (MODERATE)

7 месяцев назад
oracle-oval логотип
ELSA-2026-0002

ELSA-2026-0002: tar security update (MODERATE)

7 месяцев назад
fstec логотип
BDU:2026-00339

Уязвимость архиватора GNU Tar, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти существующие ограничения безопасности и получить доступ на перезапись файлов

CVSS3: 4.1
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:21070-1

Security update for tar

около 1 месяца назад

Уязвимостей на страницу