Vulnerability Bulletins

DSA-3778 ruby-archive-tar-minitar - security update

   
Affected software Debian
 
Michal Marek discovered that ruby-archive-tar-minitar, a Ruby librarythat provides the ability to deal with POSIX tar archive files, is proneto a directory traversal vulnerability. An attacker can take advantageof this flaw to overwrite arbitrary files during archive extraction viaa .. (dot dot) in an extracted filename.

More info:

https://www.debian.org/security/2017/dsa-3778