Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4131

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.087
EPSS Ranking 92.0%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2007-4131
  • Gnu » Tar » Version: 1.13
    cpe:2.3:a:gnu:tar:1.13
  • Gnu » Tar » Version: 1.13.11
    cpe:2.3:a:gnu:tar:1.13.11
  • Gnu » Tar » Version: 1.13.14
    cpe:2.3:a:gnu:tar:1.13.14
  • Gnu » Tar » Version: 1.13.16
    cpe:2.3:a:gnu:tar:1.13.16
  • Gnu » Tar » Version: 1.13.17
    cpe:2.3:a:gnu:tar:1.13.17
  • Gnu » Tar » Version: 1.13.18
    cpe:2.3:a:gnu:tar:1.13.18
  • Gnu » Tar » Version: 1.13.19
    cpe:2.3:a:gnu:tar:1.13.19
  • Gnu » Tar » Version: 1.13.25
    cpe:2.3:a:gnu:tar:1.13.25
  • Gnu » Tar » Version: 1.13.5
    cpe:2.3:a:gnu:tar:1.13.5
  • Gnu » Tar » Version: 1.14
    cpe:2.3:a:gnu:tar:1.14
  • Gnu » Tar » Version: 1.14.90
    cpe:2.3:a:gnu:tar:1.14.90
  • Gnu » Tar » Version: 1.15
    cpe:2.3:a:gnu:tar:1.15
  • Gnu » Tar » Version: 1.15.1
    cpe:2.3:a:gnu:tar:1.15.1
  • Gnu » Tar » Version: 1.15.90
    cpe:2.3:a:gnu:tar:1.15.90
  • Gnu » Tar » Version: 1.15.91
    cpe:2.3:a:gnu:tar:1.15.91
  • Gnu » Tar » Version: 1.16
    cpe:2.3:a:gnu:tar:1.16
  • Redhat » Enterprise Linux » Version: 4.0
    cpe:2.3:o:redhat:enterprise_linux:4.0
  • Redhat » Enterprise Linux » Version: 5.0
    cpe:2.3:o:redhat:enterprise_linux:5.0
  • Redhat » Enterprise Linux Desktop » Version: 5.0
    cpe:2.3:o:redhat:enterprise_linux_desktop:5.0
  • Rpath » Rpath Linux » Version: 1
    cpe:2.3:o:rpath:rpath_linux:1


Contact Us

Shodan ® - All rights reserved