GNU Tar Hostile Destination Path Vulnerability
BID:3024
Info
GNU Tar Hostile Destination Path Vulnerability
| Bugtraq ID: | 3024 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1267 CVE-2001-1267 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2001 12:00AM |
| Updated: | Mar 19 2015 09:15AM |
| Credit: | Reported by 3APA3A <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 GNU tar 1.13.19 GNU tar 1.13.18 GNU tar 1.13.17 GNU tar 1.13.16 GNU tar 1.13.14 GNU tar 1.13.11 GNU tar 1.13.5 GNU tar 1.13 Foresight Linux Foresight Linux 1.1 Allot NetEnforcer 4.2.1 Allot NetEnforcer 4.2 |
| Not Vulnerable: |
GNU tar 1.13.25 Allot NetEnforcer 4.2.4 |
Discussion
GNU Tar Hostile Destination Path Vulnerability
GNU tar contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item that points outside the expected directory scope, an attacker can cause the file to be extracted to arbitrary locations on the filesystem, including paths containing system binaries and other sensitive or confidential information.
By default, tar will overwrite existing files without warning the user. Since tar can override umask settings, the output file can be rendered executable.
An attacker can exploit this issue to create or overwrite binaries in any desired location. The attacker may be able to elevate privileges, potentially to 'root'.
Versions prior to GNU Tar 1.13.19 are affected.
GNU tar contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item that points outside the expected directory scope, an attacker can cause the file to be extracted to arbitrary locations on the filesystem, including paths containing system binaries and other sensitive or confidential information.
By default, tar will overwrite existing files without warning the user. Since tar can override umask settings, the output file can be rendered executable.
An attacker can exploit this issue to create or overwrite binaries in any desired location. The attacker may be able to elevate privileges, potentially to 'root'.
Versions prior to GNU Tar 1.13.19 are affected.
Exploit / POC
GNU Tar Hostile Destination Path Vulnerability
An exploit is not required.
An exploit is not required.
References
GNU Tar Hostile Destination Path Vulnerability
References:
References:
- 47800 (Sun Microsystems)
- SECURITY.NNOV: directory traversal and path globing in multiple archivers (3APA3A <[email protected]>)
- Re: Allot Netenforcer problems, GNU TAR flaw (Felix Radensky
)