Vulnerability Bulletins |
DSA-3778 ruby-archive-tar-minitar - security update |
|
| Affected software | Debian |
|
Michal Marek discovered that ruby-archive-tar-minitar, a Ruby librarythat provides the ability to deal with POSIX tar archive files, is proneto a directory traversal vulnerability. An attacker can take advantageof this flaw to overwrite arbitrary files during archive extraction viaa .. (dot dot) in an extracted filename. More info: https://www.debian.org/security/2017/dsa-3778 |
|






