Boletines de Vulnerabilidades

DSA-2863 libtar - directory traversal


Información sobre el sistema

   
Software afectado Debian

Descripción

A directory traversal attack was reported against libtar, a C library formanipulating tar archives. The application does not validate thefilenames inside the tar archive, allowing to extract files in arbitrarypath. An attacker can craft a tar file to override files beyond thetar_extract_glob and tar_extract_all prefix parameter.

More info:

http://www.debian.org/security/2014/dsa-2863

Identificadores estándar

Propiedad Valor
CVE CVE-2013-4420 and DSA-2863.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-02-19

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT