5.8
CVSSv2

CVE-2013-4420

Published: 20/02/2014 Updated: 20/02/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and previous versions allow remote malicious users to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

feep libtar 1.2.16

feep libtar 1.2.17

feep libtar 1.2.18

feep libtar 1.2.19

feep libtar 1.2.11

feep libtar 1.2.14

feep libtar 1.2.13

feep libtar 1.2.15

feep libtar

Vendor Advisories

Debian Bug report logs - #731860 libtar: CVE-2013-4420: directory traversal when extracting archives Package: src:libtar; Maintainer for src:libtar is Magnus Holmgren <holmgren@debianorg>; Reported by: Raphael Geissert <geissert@debianorg> Date: Tue, 10 Dec 2013 15:30:02 UTC Severity: grave Tags: patch, security F ...
A directory traversal attack was reported against libtar, a C library for manipulating tar archives The application does not validate the filenames inside the tar archive, allowing to extract files in arbitrary path An attacker can craft a tar file to override files beyond the tar_extract_glob and tar_extract_all prefix parameter For the oldstab ...
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1220 and earlier allow remote attackers to overwrite arbitrary files via a (dot dot) in a crafted tar file ...