CVE-2013-4420

EPSS 0.38%

libtar - directory traversal

發布日:2014/2/20修改日:2026/3/9
也稱為:DSA-2863-1DEBIAN-CVE-2013-4420

描述

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

受影響套件(2)

參考連結(1)