Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tar | Sep 20, 2017 | Dec 9, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 9, 2016 |
| Debian | — | Upgrade tar | Mar 31, 2017 | Nov 1, 2016 |
| Gentoo Linux | — | Upgrade app-arch/tar. | Oct 30, 2017 | Dec 9, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade tar | Dec 4, 2019 | Dec 9, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade tar | Dec 18, 2019 | Dec 9, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade tar | Nov 19, 2019 | Dec 9, 2016 |
| Oracle Solaris | — | Upgrade archiver/gnu-tar to version 1.28-0.175.3.21.0.4.0 on Solaris 11.3 | Jun 20, 2017 | Dec 9, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 27, 2016 |
| Suse | — | Upgrade tarUpgrade tar-langUpgrade tar-rmt | Nov 24, 2016 | Nov 24, 2016 |
| Ubuntu | — | Upgrade tar | Nov 21, 2016 | Nov 21, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 9, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub