Security Advisory

CVE-2002-0399

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2002-10-01 04:00:00
Last updated 2024-08-08 02:49:28
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.