Impact
gpgtar, the archiving component of GnuPG, can follow symbolic links when extracting an archive with the --directory flag. A malicious archive that includes a symlink pointing outside the selected extraction directory can cause gpgtar to create or overwrite files that are outside the intended boundary. This flaw allows an attacker to write arbitrary data to locations where the extracting user has write permission, potentially compromising configuration files or other sensitive data, but the impact is limited to the scope of the user’s filesystem rights.
Affected Systems
The flaw exists in all GnuPG versions prior to 2.5.19. Every build distributed under the GnuPG project is affected until the public release that removes the vulnerable behaviour, version 2.5.19 and later, contains the fix.
Risk and Exploitability
The CVSS score of 3.6 indicates low‑to‑moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to supply a crafted archive to a user who runs gpgtar with the --directory switch inside a directory that already contains a pre‑existing symlink. The overwrite is constrained by the extracting user’s filesystem permissions, so the attacker can only affect files in locations where that user can write.
OpenCVE Enrichment