CVE-2005-1918

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an “incorrect optimization” that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving ”/../” sequences with a leading ”/”.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
tar 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected