Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%