GNU Tar Hostile Destination Path Vulnerability

Solution:
NOTE: Allot NetEnforcer includes a vulnerable version of GNU tar. The vendor has addressed this issue in NetEnforcer 4.2.4 by using GNU cpio instead. The vendor has also announced that Allot NetEnforcer will include updated tar packages as soon as GNU provides them.

Please see the referenced advisories for more information.


GNU tar 1.13

GNU tar 1.13.11

GNU tar 1.13.14

GNU tar 1.13.16

GNU tar 1.13.17

GNU tar 1.13.18

GNU tar 1.13.19

GNU tar 1.13.5


 

Privacy Statement
Copyright 2010, SecurityFocus