Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian DSA-3702-1 Moderate: TAR Path Bypass Risk Mitigation

debian
Calendar Grey November 1, 2016
Debian Logo
Enhance tar distributions on Debian instances to address a vulnerability that permits unauthorized path traversal by malicious entities.
Harry Sintonen discovered that GNU tar does not properly handle member names containing '..', thus allowing an attacker to bypass the path names specified on the command line and r...

Summary

For the stable distribution (jessie), this problem has been fixed in
version 1.27.1-2+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 1.29b-1.1.

We recommend that you upgrade your tar packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: tar
CVE ID: CVE-2016-6321

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here