← Vulnerability feed

Vulnerability record · CVE-2005-2541 · published 10 August 2005

CVE-2005-2541: Gnu tar vulnerability

Gnu · Tar

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

10.0 CVSS 2.0 High EPSS 4.0% · top 9.8%
10.0CVSS 2.0 base score
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2541 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2016-6321Gnu tar path traversal vulnerabilityDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…EPSS 16%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%6.8CVE-2010-0624Gnu cpio memory buffer overflow vulnerabilityHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…EPSS 4.7%6.8CVE-2007-4131Gnu tar vulnerabilityDirectory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…EPSS 2.7%6.2CVE-2023-39804Gnu tar vulnerabilityIn GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.EPSS 0.28%5.5CVE-2026-5704Gnu tar unrestricted file upload vulnerabilityA flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…EPSS 0.40%5.5CVE-2022-48303Gnu tar out-of-bounds read vulnerabilityGNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2005-2541), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.