|
|
| |
|
| |
tar: symlink vulnerability
| Package(s): | tar |
CVE #(s): | CVE-2006-6097
|
| Created: | November 28, 2006 |
Updated: | December 20, 2006 |
| Description: |
Teemu Salmela discovered that tar still handles the deprecated
GNUTYPE_NAMES record type. This record type could be used to create
symlinks that would be followed while unpacking a tar archive. If a user
or an automated system were tricked into unpacking a specially crafted tar
file, arbitrary files could be overwritten with user privileges. |
| Alerts: |
|
( Log in to post comments)
|
|
|