VDB
JLSEC-2025-197
JLSEC-2025-197
PUBLISHED
CVSS 4.099999904632568 MEDIUM
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a...
Risk Scores
CVSS 3.1
4.099999904632568
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | Tar_jll | 0 |
| Julia | Tar_jll | 0, 0 |
Timeline
- Nov 3, 2025 CVE Published
- Jul 23, 2026 CVE Updated
References
- http://www.openwall.com/lists/oss-security/2025/11/01/6 url
- https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md url
- https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html url
- https://www.gnu.org/software/tar/ url
- https://www.gnu.org/software/tar/manual/html_node/Integrity.html url
- https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html url