ruby-archive-tar-minitar: file overwrites
| Package(s): | ruby-archive-tar-minitar | CVE #(s): | CVE-2016-10173 | ||||||||||||||||||||
| Created: | January 31, 2017 | Updated: | February 22, 2017 | ||||||||||||||||||||
| Description: | From the Debian LTS advisory:
It has been found that rubygem archive-tar-minitar allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
