Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

github логотип

GHSA-4f5j-wqjr-hx49

около 2 месяцев назад

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

CVSS3: 4.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2714-1

3 месяца назад

Security update for tar

EPSS: Низкий
github логотип

GHSA-jqqw-37x4-9rwj

6 месяцев назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21070-1

3 месяца назад

Security update for tar

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f5j-wqjr-hx49

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2714-1

Security update for tar

0%
Низкий
3 месяца назад
github логотип
GHSA-jqqw-37x4-9rwj

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21070-1

Security update for tar

3 месяца назад

Уязвимостей на страницу