CVE Vulnerabilities

CVE-2002-0399

Published: Oct 10, 2002 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) /.. or (2) ./.. string, which removes the leading slash but leaves the .., a variant of CVE-2001-1267.

Affected Software

Name Vendor Start Version End Version
Tar Gnu 1.13.25 (including) 1.13.25 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Linux 6.2 RedHat *
Red Hat Linux 7.0 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Tar Ubuntu dapper *
Tar Ubuntu devel *
Tar Ubuntu edgy *
Tar Ubuntu feisty *

References