Bug 251921 - (CVE-2007-4131) CVE-2007-4131 tar directory traversal vulnerability
CVE-2007-4131 tar directory traversal vulnerability
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,source=vendorsec,repo...
: Security
Depends On: 252967 252968 252969 252970 253684 253685
Blocks:
  Show dependency treegraph
 
Reported: 2007-08-13 10:23 EDT by Tomas Hoger
Modified: 2010-02-16 00:09 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-08-31 03:40:30 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
contains_dot_dot patch (531 bytes, patch)
2007-08-13 10:25 EDT, Tomas Hoger
no flags Details | Diff

  None (edit)
Description Tomas Hoger 2007-08-13 10:23:06 EDT
Directory traversal vulnerability was discovered in GNU tar.  Vulnerability can
be exploited by specially crafted tar archive to overwrite arbitrary file
writable by user running tar.  Problem occurs in contains_dot_dot function,
which does not properly check names of directory symlinks.

Acknowledgements:

Red Hat would like to thank Dmitry V. Levin for reporting this issue.
Comment 1 Tomas Hoger 2007-08-13 10:25:52 EDT
Created attachment 161175 [details]
contains_dot_dot patch

Patch by Dmitry V. Levin used by Owl.
Comment 4 Tomas Hoger 2007-08-20 09:33:10 EDT
Patch is in upstream cvs, embargo removed.
Comment 8 Tomas Hoger 2007-08-23 08:56:15 EDT
This issue did not affect tar packages as distributed with Red Hat
Enterprise Linux 2.1 or 3.
Comment 9 Tomas Hoger 2007-08-31 03:40:30 EDT
Issue fixed on all supported platforms, closing Security Response bug.

Note You need to log in before you can comment on or make changes to this bug.