VYPR
Unrated severityNVD Advisory· Published Oct 10, 2002· Updated Apr 16, 2026

CVE-2002-0399

CVE-2002-0399

Description

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.

Affected products

1
  • cpe:2.3:a:gnu:tar:1.13.25:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

18

News mentions

0

No linked articles in our index yet.