CVE-2016-6321

Description

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
11.143

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GNU Tar 1.15.1Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.14Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15.90Windows
Vulnerabilities CVE-2006-6097,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.16Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15.91Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.16.1Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.17Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.18Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.19Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.20Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.21Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.22Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.23Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.24Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.25Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.26Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.27Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.27.1Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.28Windows
Vulnerabilities CVE-2016-6321 are affected in GNU Tar 1.29Windows
GNU version of the tar archiving utility (USN-3132-1) tar_1.26-4ubuntu1.1_i386.debLinux
GNU version of the tar archiving utility (USN-3132-1) tar_1.26-4ubuntu1.1_amd64.debLinux
GNU version of the tar archiving utility (USN-3132-1) tar_1.27.1-1ubuntu0.1_i386.debLinux
GNU version of the tar archiving utility (USN-3132-1) tar_1.27.1-1ubuntu0.1_amd64.debLinux
GNU version of the tar archiving utility (USN-3132-1) tar_1.28-2.1ubuntu0.1_i386.debLinux
GNU version of the tar archiving utility (USN-3132-1) tar_1.28-2.1ubuntu0.1_amd64.debLinux
tar security update(DSA-3702-1) tar_1.27.1-2+deb8u1_kfreebsd-i386.debLinux
tar security update(DSA-3702-1) tar_1.27.1-2+deb8u1_kfreebsd-amd64.debLinux
SUSE-SU-2016:2895-1(SUSE Linux Enterprise Server 11-SP4 ) tar-1.26-1.2.10.1.x86_64.rpmLinux
SUSE-SU-2016:2896-1(SUSE Linux Enterprise Desktop 12-SP1 ) tar-1.27.1-11.1.x86_64.rpmLinux
SUSE-SU-2016:2896-1(SUSE Linux Enterprise Desktop 12-SP1 ) tar-debuginfo-1.27.1-11.1.x86_64.rpmLinux
SUSE-SU-2016:2896-1(SUSE Linux Enterprise Desktop 12-SP1 ) tar-debugsource-1.27.1-11.1.x86_64.rpmLinux
SUSE-SU-2016:2896-1(SUSE Linux Enterprise Desktop 12-SP1 ) tar-lang-1.27.1-11.1.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234