[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2863-1 libtar -- directory traversal

ID: oval:org.secpod.oval:def:601217Date: (C)2014-02-21   (M)2022-10-10
Class: PATCHFamily: unix




A directory traversal attack was reported against libtar, a C library for manipulating tar archives. The application does not validate the filenames inside the tar archive, allowing to extract files in arbitrary path. An attacker can craft a tar file to override files beyond the tar_extract_glob and tar_extract_all prefix parameter.

Platform:
Debian 7.0
Debian 6.0
Product:
libtar
Reference:
DSA-2863-1
CVE-2013-4420
CVE    1
CVE-2013-4420
CPE    12
cpe:/a:feep:libtar
cpe:/a:feep:libtar:1.2.18
cpe:/a:feep:libtar:1.2.19
cpe:/o:debian:debian_linux:6.0
...

© SecPod Technologies