CVE-2002-0399
CVE-2002-0399
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538http://marc.info/?l=bugtraq&m=103419290219680&w=2http://secunia.com/advisories/19130http://secunia.com/advisories/26604http://secunia.com/advisories/26673http://secunia.com/advisories/26987https://issues.rpath.com/browse/RPL-1631http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000928.1-1http://www.iss.net/security_center/static/10224.phphttp://www.linuxsecurity.com/advisories/other_advisory-2400.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2002:066