CVE-2013-4420
Published: 20 February 2014
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Notes
Author | Note |
---|---|
jdstrand | no patch as of 2013-10-11 |
Priority
Status
Package | Release | Status |
---|---|---|
libtar Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was not-affected [1.2.20-3 ])
|
|
upstream |
Released
(1.2.20-3)
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Ignored
(end of life)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Not vulnerable
(1.2.20-4)
|
|
yakkety |
Not vulnerable
(1.2.20-6)
|
|
zesty |
Not vulnerable
|