CVE-2016-6321 PUBLISHED

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

EPSS 11.14% · 93.4th percentile

Risk Scores

EPSS Score
11.14%
93.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTStar0, 1.26+dfsg-8, 1.27-3
Ubuntu:16.04:LTStar0, 1.27.1-2, 1.28-2ubuntu1

Timeline

References

Open in Interactive Console →