Release date: 2013-10-09
Updated on:
Affected Systems:
Feep libtar <= 1.2.20
Feep libtar
Description:
--------------------------------------------------------------------------------
Bugtraq id: 62955
CVE (CAN) ID: CVE-2013-4420
Libtar is the C language library used to operate POSIX tar files. It can be compressed into tar files or released from tar files.
Libtar 1.2.20 and earlier versions do not effectively verify the path prefix in the "tar_extract_glob ()" and "tar_extract_all ()" functions, which can overwrite arbitrary files.
<* Source: Timo Warns (<warns@pre-sense.de>)
Link: http://secunia.com/advisories/55138/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Feep
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.feep.net/libtar/
Https://lists.feep.net: 8080/pipermail/libtar/2013-October/000359.html