CVE-2007-4131
CVE-2007-4131
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=251921http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://secunia.com/advisories/26573http://secunia.com/advisories/26590http://secunia.com/advisories/26603http://secunia.com/advisories/26604http://secunia.com/advisories/26655http://secunia.com/advisories/26673http://secunia.com/advisories/26674http://secunia.com/advisories/26781http://secunia.com/advisories/26822