Back to search
CVE-2016-10173
Published: Feb 1, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20170124 CVE request: rubygem minitar: directory traversal vulnerability
mailing-list
x_refsource_MLIST
GLSA-201702-32
vendor-advisory
x_refsource_GENTOO
95874
vdb-entry
x_refsource_BID
https://github.com/halostatue/minitar/issues/16
x_refsource_CONFIRM
[oss-security] 20170129 Re: CVE request: rubygem minitar: directory traversal vulnerability
mailing-list
x_refsource_MLIST
DSA-3778
vendor-advisory
x_refsource_DEBIAN
https://puppet.com/security/cve/cve-2016-10173
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now