docs.info.apple.comConfirmation
http://docs.info.apple.com/article.html?artnum=305214 CVE-2006-6097
GNU Tar 1.1x - 'GNUTYPE_NAMES' Directory Traversal
Record summary
CVE-2006-6097 has a selected CVSS score of 4.0; EIP currently links 1 catalogued exploit.
Description
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU Tar 1.1x - 'GNUTYPE_NAMES' Directory TraversalExploitDB exploitby Teemu SalmelaNot analyzed1 file
References
Showing 12 of 43kb.vmware.comConfirmation
http://kb.vmware.com/KanisaPlatform/Publishing/817/2240267_f.SAL_Public.html APPLE-SA-2007-03-13Vendor advisory
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html 20061121 GNU tar directory traversalmailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050812.html RHSA-2006:0749Vendor advisory
http://rhn.redhat.com/errata/RHSA-2006-0749.html 23115Third-party advisory
http://secunia.com/advisories/23115 23117Third-party advisory
http://secunia.com/advisories/23117 23142Third-party advisory
http://secunia.com/advisories/23142 23146Third-party advisory
http://secunia.com/advisories/23146 23163Third-party advisory
http://secunia.com/advisories/23163 23173Third-party advisory
http://secunia.com/advisories/23173 23198Third-party advisory
http://secunia.com/advisories/23198