← Back

Tardiff

tardiff

Vendor: Tardiff Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Tardiff Project
2Debian Linux
Tardiff
May 6, 2026
May 6, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
2Debian
Tardiff Project
2Debian Linux
Tardiff
May 6, 2026
May 6, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.