[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3702-1 tar -- tar

ID: oval:org.secpod.oval:def:602656Date: (C)2016-11-04   (M)2023-12-20
Class: PATCHFamily: unix




Harry Sintonen discovered that GNU tar does not properly handle member names containing "..", thus allowing an attacker to bypass the path names specified on the command line and replace files and directories in the target directory.

Platform:
Debian 8.x
Product:
tar
Reference:
DSA-3702-1
CVE-2016-6321
CVE    1
CVE-2016-6321
CPE    2
cpe:/a:gnu:tar
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies