Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Enterprise_linux | Redhat | 4.0 (including) | 4.0 (including) |
| Enterprise_linux | Redhat | 5.0 (including) | 5.0 (including) |
| Enterprise_linux_desktop | Redhat | 5.0 (including) | 5.0 (including) |
| Rpath_linux | Rpath | 1 (including) | 1 (including) |
| Red Hat Enterprise Linux 4 | RedHat | tar-0:1.14-12.5.1.RHEL4 | * |
| Red Hat Enterprise Linux 5 | RedHat | tar-2:1.15.1-23.0.1.el5 | * |
| Tar | Ubuntu | dapper | * |
| Tar | Ubuntu | devel | * |
| Tar | Ubuntu | edgy | * |
| Tar | Ubuntu | feisty | * |