← Vulnerability feed

Vulnerability record · CVE-2006-6097 · published 24 November 2006

CVE-2006-6097: Gnu tar vulnerability

Gnu · Tar

GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.

4.0 CVSS 2.0 Medium EPSS 11% · top 4.2%
4.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
86References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.

AV:N/AC:H/Au:N/C:N/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc
http://docs.info.apple.com/article.html?artnum=305214
http://kb.vmware.com/KanisaPlatform/Publishing/817/2240267_f.SAL_Public.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050812.html Exploit
http://rhn.redhat.com/errata/RHSA-2006-0749.html
http://secunia.com/advisories/23115
http://secunia.com/advisories/23117
http://secunia.com/advisories/23142
http://secunia.com/advisories/23146
http://secunia.com/advisories/23163
http://secunia.com/advisories/23173
http://secunia.com/advisories/23198
http://secunia.com/advisories/23209
http://secunia.com/advisories/23314
http://secunia.com/advisories/23443
http://secunia.com/advisories/23514
http://secunia.com/advisories/23911
http://secunia.com/advisories/24479
http://secunia.com/advisories/24636
http://security.freebsd.org/advisories/FreeBSD-SA-06:26.gtar.asc
http://security.gentoo.org/glsa/glsa-200612-10.xml
http://securityreason.com/securityalert/1918
http://securitytracker.com/id?1017423
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.469379
http://support.avaya.com/elmodocs2/security/ASA-2007-015.htm
http://www.debian.org/security/2006/dsa-1223
http://www.mandriva.com/security/advisories?name=MDKSA-2006:219
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.038.html
http://www.securityfocus.com/archive/1/453286/100/0/threaded
http://www.securityfocus.com/archive/1/464268/100/0/threaded
http://www.securityfocus.com/bid/21235 Exploit
http://www.trustix.org/errata/2006/0068/
http://www.ubuntu.com/usn/usn-385-1
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vmware.com/support/esx25/doc/esx-254-200702-patch.html
http://www.vupen.com/english/advisories/2006/4717
http://www.vupen.com/english/advisories/2006/5102
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2007/1171

Track CVE-2006-6097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2541Gnu tar vulnerabilityTar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.EPSS 4.0%7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2016-6321Gnu tar path traversal vulnerabilityDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…EPSS 16%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%6.8CVE-2010-0624Gnu cpio memory buffer overflow vulnerabilityHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…EPSS 4.7%6.8CVE-2007-4131Gnu tar vulnerabilityDirectory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…EPSS 2.7%6.2CVE-2023-39804Gnu tar vulnerabilityIn GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.EPSS 0.28%5.5CVE-2026-5704Gnu tar unrestricted file upload vulnerabilityA flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2006-6097), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.