Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Debian DSA-3702-1 Moderate: TAR Path Bypass Risk Mitigation

debian
Calendar Grey November 1, 2016
Scroller Debian
Enhance tar distributions on Debian instances to address a vulnerability that permits unauthorized path traversal by malicious entities.
Harry Sintonen discovered that GNU tar does not properly handle member names containing '..', thus allowing an attacker to bypass the path names specified on the command line and r...

Summary

For the stable distribution (jessie), this problem has been fixed in
version 1.27.1-2+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 1.29b-1.1.

We recommend that you upgrade your tar packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: tar
CVE ID: CVE-2016-6321

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.