Vulnerability Bulletins

DSA-3702 tar - security update

   
Affected software Debian
 
Harry Sintonen discovered that GNU tar does not properly handle membernames containing .., thus allowing an attacker to bypass the pathnames specified on the command line and replace files and directories inthe target directory.

More info:

https://www.debian.org/security/2016/dsa-3702