Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2010-0624

Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
0
Attacker Value
Unknown

CVE-2009-2572

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.
0
Attacker Value
Unknown

CVE-2007-4131

Disclosure Date: August 25, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
0
Attacker Value
Unknown

CVE-2005-1918

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".
0
Attacker Value
Unknown

CVE-2002-1216

Disclosure Date: October 28, 2002 (last updated February 22, 2025)
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
0
Attacker Value
Unknown

CVE-2002-0399

Disclosure Date: October 10, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
0