Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Tar 安全绕过漏洞
Vulnerability Description
GNU Tar是GNU计划开发的一套用于创建tar格式文件的工具。 GNU tar 1.14至1.29版本中的‘safer_name_suffix’函数存在目录遍历漏洞,该漏洞源于程序没有正确的过滤‘file_name’参数。远程攻击者可利用该漏洞绕过既定的保护机制并写入任意代码。
CVSS Information
N/A
Vulnerability Type
N/A