CVE-2013-4420
20.02.2014, 16:55
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Vendor | Product | Version |
---|---|---|
feep | libtar | 𝑥 ≤ 1.2.20 |
feep | libtar | 1.2.11 |
feep | libtar | 1.2.13 |
feep | libtar | 1.2.14 |
feep | libtar | 1.2.15 |
feep | libtar | 1.2.16 |
feep | libtar | 1.2.17 |
feep | libtar | 1.2.18 |
feep | libtar | 1.2.19 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References