All errata/p9/ALT-PU-2020-3184-1
ALT-PU-2020-3184-1

Package update libtar in branch p9

Version1.2.20-alt2.git.6d0ab4c
Published2020-11-02
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2013-4420
MEDIUM5.8

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

Published: 2014-02-20Modified: 2026-04-29
CVSS 2.0MEDIUM 5.8
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:P