VYPR
Unrated severityNVD Advisory· Published Aug 25, 2007· Updated Apr 23, 2026

CVE-2007-4131

CVE-2007-4131

Description

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

Affected products

16
  • GNU/Tar16 versions
    cpe:2.3:a:gnu:tar:1.13:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:gnu:tar:1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.11:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.14:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.16:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.17:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.18:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.19:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.25:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.13.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.14.90:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.15.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.15.90:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.15.91:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:tar:1.16:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

38

News mentions

0

No linked articles in our index yet.