LWN.net Logo

tar: symlink vulnerability

Package(s):tar CVE #(s):CVE-2006-6097
Created:November 28, 2006 Updated:December 20, 2006
Description: Teemu Salmela discovered that tar still handles the deprecated GNUTYPE_NAMES record type. This record type could be used to create symlinks that would be followed while unpacking a tar archive. If a user or an automated system were tricked into unpacking a specially crafted tar file, arbitrary files could be overwritten with user privileges.
Alerts:
Red Hat RHSA-2006:0749-01 2006-12-19
Gentoo 200612-10 2006-12-11
OpenPKG OpenPKG-SA-2006.038 2006-12-08
Slackware SSA:2006-335-01 2006-12-04
Debian DSA-1223-1 2006-12-01
rPath rPSA-2006-0222-1 2006-11-30
Mandriva MDKSA-2006:219 2006-11-28
Ubuntu USN-385-1 2006-11-27

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds