Vulnerabilities
Vulnerable Software
Gnu:  >> Tar  >> 1.15.1  Security Vulnerabilities
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
CVSS Score
4.0
EPSS Score
0.073
Published
2006-11-24
Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
CVSS Score
5.1
EPSS Score
0.188
Published
2006-02-24
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
CVSS Score
10.0
EPSS Score
0.033
Published
2005-08-10


Contact Us

Shodan ® - All rights reserved