Vulnerability Details CVE-2013-4420
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.1%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2013-4420
-
-
cpe:2.3:a:feep:libtar:1.2.11
-
cpe:2.3:a:feep:libtar:1.2.13
-
cpe:2.3:a:feep:libtar:1.2.14
-
cpe:2.3:a:feep:libtar:1.2.15
-
cpe:2.3:a:feep:libtar:1.2.16
-
cpe:2.3:a:feep:libtar:1.2.17
-
cpe:2.3:a:feep:libtar:1.2.18
-
cpe:2.3:a:feep:libtar:1.2.19
-
cpe:2.3:a:feep:libtar:1.2.20