← Vulnerability feed

Vulnerability record · CVE-2007-4131 · published 25 August 2007

CVE-2007-4131: Gnu tar vulnerability

Gnu · Tar

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

6.8 CVSS 2.0 Medium EPSS 2.7% · top 14.4%
6.8CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
76References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=251921
http://docs.info.apple.com/article.html?artnum=307179
http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
http://secunia.com/advisories/26573
http://secunia.com/advisories/26590
http://secunia.com/advisories/26603
http://secunia.com/advisories/26604
http://secunia.com/advisories/26655
http://secunia.com/advisories/26673
http://secunia.com/advisories/26674
http://secunia.com/advisories/26781
http://secunia.com/advisories/26822
http://secunia.com/advisories/26984
http://secunia.com/advisories/27453
http://secunia.com/advisories/27861
http://secunia.com/advisories/28136
http://secunia.com/advisories/28255
http://security.FreeBSD.org/advisories/FreeBSD-SA-07:10.gtar.asc
http://security.gentoo.org/glsa/glsa-200709-09.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1
http://support.avaya.com/elmodocs2/security/ASA-2007-383.htm
http://www.debian.org/security/2007/dsa-1438
http://www.mandriva.com/security/advisories?name=MDKSA-2007:173
http://www.novell.com/linux/security/advisories/2007_18_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0860.html Patch
http://www.securityfocus.com/archive/1/477731/100/0/threaded
http://www.securityfocus.com/archive/1/477865/100/0/threaded
http://www.securityfocus.com/bid/25417
http://www.securitytracker.com/id?1018599
http://www.trustix.org/errata/2007/0026/
http://www.ubuntu.com/usn/usn-506-1
http://www.us-cert.gov/cas/techalerts/TA07-352A.html US Government Resource
http://www.vupen.com/english/advisories/2007/2958
http://www.vupen.com/english/advisories/2007/4238
https://issues.rpath.com/browse/RPL-1631
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10420
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7779
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.html
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=251921
http://docs.info.apple.com/article.html?artnum=307179

Track CVE-2007-4131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2541Gnu tar vulnerabilityTar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.EPSS 4.0%7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2016-6321Gnu tar path traversal vulnerabilityDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…EPSS 16%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%6.8CVE-2010-0624Gnu cpio memory buffer overflow vulnerabilityHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…EPSS 4.7%6.2CVE-2023-39804Gnu tar vulnerabilityIn GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.EPSS 0.28%5.5CVE-2026-5704Gnu tar unrestricted file upload vulnerabilityA flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…EPSS 0.40%5.5CVE-2022-48303Gnu tar out-of-bounds read vulnerabilityGNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2007-4131), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.