Definition
New Search
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file probably involving "/../" sequences with a leading "/".
oval:org.mitre.oval:def:9946
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file probably involving "/../" sequences with a leading "/".
Family:
unix
Status:
ACCEPTED
Platform(s):
- CentOS Linux 3
- Red Hat Enterprise Linux 3
Class:
vulnerability
Reference(s):
- CVE-2005-1918
Product(s):