← Back

CVE-2013-4420

nvd nist
Published: Feb 20, 2014Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

Affected (9)

Products: Feep: Libtar
1 product
Libtar
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Feep
Up to 1.2.20
Version 1.2.11
Version 1.2.13
Version 1.2.14
Version 1.2.15
Version 1.2.16
Version 1.2.17
Version 1.2.18
Version 1.2.19

References (6)

Timeline

No history available yet.