CVE-2006-6097
GNU tar <1.16 - Code Injection
Title source: llmDescription
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Teemu Salmela · cremotelinux
https://www.exploit-db.com/exploits/29160
References (43)
... and 23 more
Scores
EPSS
0.1044
EPSS Percentile
93.3%
Details
Status
published
Products (2)
gnu/tar
1.15.1
gnu/tar
1.16
Published
Nov 24, 2006
Tracked Since
Feb 18, 2026