tar: directory traversal by letting tar create apropriate symlinks

Related Vulnerabilities: CVE-2006-6097  

Debian Bug report logs - #399845
tar: directory traversal by letting tar create apropriate symlinks

version graph

Package: tar; Maintainer for tar is Bdale Garbee <bdale@gag.com>; Source for tar is src:tar (PTS, buildd, popcon).

Reported by: Axel Beckert <abe@deuxchevaux.org>

Date: Wed, 22 Nov 2006 12:18:06 UTC

Severity: critical

Tags: sarge, security, sid, upstream

Found in version tar/1.16-1

Fixed in version tar/1.16-2

Done: Bdale Garbee <bdale@gag.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Axel Beckert <abe@deuxchevaux.org>, Debian Security Team <team@security.debian.org>, Bdale Garbee <bdale@gag.com>:
Bug#399845; Package tar. (full text, mbox, link).


Acknowledgement sent to Axel Beckert <abe@deuxchevaux.org>:
New Bug report received and forwarded. Copy sent to Axel Beckert <abe@deuxchevaux.org>, Debian Security Team <team@security.debian.org>, Bdale Garbee <bdale@gag.com>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Axel Beckert <abe@deuxchevaux.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: tar: directory traversal by letting tar create apropriate symlinks
Date: Wed, 22 Nov 2006 12:48:03 +0100
Package: tar
Version: 1.16-1
Severity: critical
Tags: sarge, sid, upstream, security

There is a directory traversal bug in GNU tar as described in
http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050812.html
which means the creation and overwriting of files outside the expected
directory without using -P.

I could reproduce this security flaw in Sarge (tar 1.14-2.2) as well
in Sid (tar 1.16-1), so it probably is also in the version in Etch.

-- System Information:
Debian Release: 4.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.4.33.2-1-dphys-k8-smp-64gb
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages tar depends on:
ii  libc6                        2.3.6.ds1-8 GNU C Library: Shared libraries

tar recommends no packages.

-- no debconf information



Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#399845; Package tar. (full text, mbox, link).


Acknowledgement sent to Kees Cook <kees@outflux.net>:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>. (full text, mbox, link).


Message #10 received at 399845@bugs.debian.org (full text, mbox, reply):

From: Kees Cook <kees@outflux.net>
To: 399845@bugs.debian.org
Subject: patch
Date: Fri, 24 Nov 2006 11:35:43 -0800
Tags: patch

Hello!  I've reported this upstream[1] and suggested a possible patch[2] 
to disable handling of GNUTYPE_NAMES (since it is a deprecated type).

[1] https://savannah.gnu.org/bugs/index.php?18355
[2] https://savannah.gnu.org/bugs/download.php?file_id=11327

-- 
Kees Cook                                            @outflux.net



Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#399845; Package tar. (full text, mbox, link).


Acknowledgement sent to Laurent Bonnaud <bonnaud@lis.inpg.fr>:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>. (full text, mbox, link).


Message #15 received at 399845@bugs.debian.org (full text, mbox, reply):

From: Laurent Bonnaud <bonnaud@lis.inpg.fr>
To: 399845@bugs.debian.org
Subject: Re: tar: directory traversal by letting tar create apropriate symlinks
Date: Thu, 30 Nov 2006 19:51:26 +0100
Hi,

this bug is CVE-2006-6097:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6097

-- 
Laurent Bonnaud.
http://www.lis.inpg.fr/pages_perso/bonnaud/





Reply sent to Bdale Garbee <bdale@gag.com>:
You have taken responsibility. (full text, mbox, link).


Notification sent to Axel Beckert <abe@deuxchevaux.org>:
Bug acknowledged by developer. (full text, mbox, link).


Message #20 received at 399845-close@bugs.debian.org (full text, mbox, reply):

From: Bdale Garbee <bdale@gag.com>
To: 399845-close@bugs.debian.org
Subject: Bug#399845: fixed in tar 1.16-2
Date: Fri, 01 Dec 2006 16:47:03 +0000
Source: tar
Source-Version: 1.16-2

We believe that the bug you reported is fixed in the latest version of
tar, which is due to be installed in the Debian FTP archive:

tar_1.16-2.diff.gz
  to pool/main/t/tar/tar_1.16-2.diff.gz
tar_1.16-2.dsc
  to pool/main/t/tar/tar_1.16-2.dsc
tar_1.16-2_i386.deb
  to pool/main/t/tar/tar_1.16-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 399845@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bdale Garbee <bdale@gag.com> (supplier of updated tar package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Fri,  1 Dec 2006 09:19:02 -0700
Source: tar
Binary: tar
Architecture: source i386
Version: 1.16-2
Distribution: unstable
Urgency: high
Maintainer: Bdale Garbee <bdale@gag.com>
Changed-By: Bdale Garbee <bdale@gag.com>
Description: 
 tar        - GNU tar
Closes: 399845
Changes: 
 tar (1.16-2) unstable; urgency=high
 .
   * patch from Kees Cook via upstream to disable handling of GNUTYPE_NAMES
     by default and add a new command-line switch --allow-name-mangling to
     re-enable it, as a fix for directory traversal bug (CVE-2006-6097),
     closes: #399845
Files: 
 fc5061b6d891f1daf86fd45cb8e3fd72 569 utils required tar_1.16-2.dsc
 ec350ddfa0d12e11b9f9d64dccbb552f 30534 utils required tar_1.16-2.diff.gz
 903e02f11db634f48f58cb170d43f5e1 672060 utils required tar_1.16-2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFFcFtFZKfAp/LPAagRAogaAJsHcT8uvrF/GlvnZLJ+Go8Ri7Lf7wCfUOSt
308GOg7JTcajeJqkLWSDme0=
=m02k
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 25 Jun 2007 11:10:25 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:43:48 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.