Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 4.0 (including) | 4.0 (including) |
Enterprise_linux | Redhat | 5.0 (including) | 5.0 (including) |
Enterprise_linux_desktop | Redhat | 5.0 (including) | 5.0 (including) |
Rpath_linux | Rpath | 1 (including) | 1 (including) |
Red Hat Enterprise Linux 4 | RedHat | tar-0:1.14-12.5.1.RHEL4 | * |
Red Hat Enterprise Linux 5 | RedHat | tar-2:1.15.1-23.0.1.el5 | * |
Tar | Ubuntu | dapper | * |
Tar | Ubuntu | devel | * |
Tar | Ubuntu | edgy | * |
Tar | Ubuntu | feisty | * |