Description
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Published: 2007-08-25
Score: 6.8 Medium
EPSS: 11.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1438-1 New tar packages fix several vulnerabilities
EUVD EUVD EUVD-2007-4115 Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Ubuntu USN Ubuntu USN USN-506-1 tar vulnerability
References
Link Providers
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=251921 cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=307179 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html cve-icon cve-icon
http://secunia.com/advisories/26573 cve-icon cve-icon
http://secunia.com/advisories/26590 cve-icon cve-icon
http://secunia.com/advisories/26603 cve-icon cve-icon
http://secunia.com/advisories/26604 cve-icon cve-icon
http://secunia.com/advisories/26655 cve-icon cve-icon
http://secunia.com/advisories/26673 cve-icon cve-icon
http://secunia.com/advisories/26674 cve-icon cve-icon
http://secunia.com/advisories/26781 cve-icon cve-icon
http://secunia.com/advisories/26822 cve-icon cve-icon
http://secunia.com/advisories/26984 cve-icon cve-icon
http://secunia.com/advisories/27453 cve-icon cve-icon
http://secunia.com/advisories/27861 cve-icon cve-icon
http://secunia.com/advisories/28136 cve-icon cve-icon
http://secunia.com/advisories/28255 cve-icon cve-icon
http://security.FreeBSD.org/advisories/FreeBSD-SA-07:10.gtar.asc cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200709-09.xml cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-383.htm cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1438 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:173 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_18_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0860.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/477731/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/477865/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25417 cve-icon cve-icon
http://www.securitytracker.com/id?1018599 cve-icon cve-icon
http://www.trustix.org/errata/2007/0026/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-506-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-352A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2958 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4238 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1631 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-4131 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10420 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7779 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-4131 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.html cve-icon cve-icon
History

No history.

Subscriptions

Gnu Tar
Redhat Enterprise Linux Enterprise Linux Desktop
Rpath Rpath Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T14:46:38.940Z

Reserved: 2007-08-02T00:00:00.000Z

Link: CVE-2007-4131

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-08-25T00:17:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-4131

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-08-12T00:00:00Z

Links: CVE-2007-4131 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses