GNU Tar Hostile Destination Path Variant Vulnerability
BID:5834
Info
GNU Tar Hostile Destination Path Variant Vulnerability
| Bugtraq ID: | 5834 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0399 CVE-2005-1918 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2002 12:00AM |
| Updated: | Oct 01 2007 07:49PM |
| Credit: | This variant issue was reported in a Red Hat advisory. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Enterprise Server 9-SP3 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 10.SP1 S.u.S.E. Linux Enterprise Server 10 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 GNU tar 1.13.25 Foresight Linux Foresight Linux 1.1 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya Converged Communications Server 2.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 |
| Not Vulnerable: | |
Discussion
GNU Tar Hostile Destination Path Variant Vulnerability
GNU 'tar' 1.13.25 contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item that points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem, including paths containing system binaries and other sensitive or confidential information.
An attacker could use this to create or overwrite binaries in any desired location.
This issue is a variant of the vulnerability described in BID 3024. It is not known whether earlier versions are also affected by this variant.
GNU 'tar' 1.13.25 contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item that points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem, including paths containing system binaries and other sensitive or confidential information.
An attacker could use this to create or overwrite binaries in any desired location.
This issue is a variant of the vulnerability described in BID 3024. It is not known whether earlier versions are also affected by this variant.
Exploit / POC
GNU Tar Hostile Destination Path Variant Vulnerability
There is no exploit required.
There is no exploit required.
References
GNU Tar Hostile Destination Path Variant Vulnerability
References:
References:
- 47800 (Sun Microsystems)
- ASA-2006-110 - tar security update (RHSA-2006-0195) (Avaya)
- RHSA-2006:0195-8 - tar security update (RedHat)