Red Hat Customer Portal

Skip to main content

CVE-2005-1918

The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".

Details Source

Mitre

Public Date

2003-07-21 00:00:00

Impact

Low

Bugzilla

CVE-2005-1918 tar archive path traversal issue

Bugzilla ID

140 589

CVSS Status

draft

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (tar) RHSA-2006:0195 2006-02-21
Red Hat Enterprise Linux 2.1 (tar) RHSA-2006:0195 2006-02-21