Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-12-09T22:00:00

Updated: 2024-08-06T01:29:18.337Z

Reserved: 2016-07-26T00:00:00

Link: CVE-2016-6321

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-12-09T22:59:00.170

Modified: 2023-02-13T04:50:12.540

Link: CVE-2016-6321

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-10-27T00:00:00Z

Links: CVE-2016-6321 - Bugzilla