CVE-2013-4420

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
feeplibtar
𝑥
≤ 1.2.20
feeplibtar
1.2.11
feeplibtar
1.2.13
feeplibtar
1.2.14
feeplibtar
1.2.15
feeplibtar
1.2.16
feeplibtar
1.2.17
feeplibtar
1.2.18
feeplibtar
1.2.19
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libtar
bookworm
1.2.20-8
fixed
bullseye
1.2.20-8
fixed
sid
1.2.20-8.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libtar
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
ignored