Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ruby-minitarUpgrade ruby-archive-tar-minitar | Feb 1, 2017 | Jan 31, 2017 |
| Gentoo Linux | — | Upgrade dev-ruby/archive-tar-minitar. | Oct 30, 2017 | Feb 1, 2017 |
| Suse | — | Upgrade ruby2.1-rubygem-archive-tar-minitar | Feb 10, 2017 | Jan 31, 2017 |
| Ubuntu | — | Upgrade ruby-minitarUpgrade ruby-archive-tar-minitar | Nov 19, 2024 | Feb 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub