Public Date:

The MITRE CVE dictionary describes this issue as:

The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".

Find out more about CVE-2005-1918 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux version 3 (tar) RHSA-2006:0195 2006-02-21
Red Hat Enterprise Linux version 2.1 (tar) RHSA-2006:0195 2006-02-21