← Vulnerability feed

Vulnerability record · CVE-2016-6321 · published 9 December 2016

CVE-2016-6321: Gnu tar path traversal vulnerability

Gnu · Tar

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

7.5 CVSS 3.1 High EPSS 16% · top 3.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.savannah.gnu.org/cgit/tar.git/commit/?id=7340f67b9860ea0531c1450e5aa261c50f67165d Issue TrackingPatch
http://lists.gnu.org/archive/html/bug-tar/2016-10/msg00016.html Mailing ListVendor Advisory
http://packetstormsecurity.com/files/139370/GNU-tar-1.29-Extract-Pathname-Bypass.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Oct/102 Mailing ListPatchThird Party Advisory
http://seclists.org/fulldisclosure/2016/Oct/96 Mailing ListThird Party Advisory
http://www.debian.org/security/2016/dsa-3702
http://www.securityfocus.com/bid/93937 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-3132-1
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.ap
https://security.gentoo.org/glsa/201611-19
https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt Third Party Advisory
http://git.savannah.gnu.org/cgit/tar.git/commit/?id=7340f67b9860ea0531c1450e5aa261c50f67165d Issue TrackingPatch
http://lists.gnu.org/archive/html/bug-tar/2016-10/msg00016.html Mailing ListVendor Advisory
http://packetstormsecurity.com/files/139370/GNU-tar-1.29-Extract-Pathname-Bypass.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Oct/102 Mailing ListPatchThird Party Advisory
http://seclists.org/fulldisclosure/2016/Oct/96 Mailing ListThird Party Advisory
http://www.debian.org/security/2016/dsa-3702
http://www.securityfocus.com/bid/93937 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-3132-1
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.ap
https://security.gentoo.org/glsa/201611-19
https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt Third Party Advisory

Track CVE-2016-6321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2541Gnu tar vulnerabilityTar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.EPSS 4.0%7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%6.8CVE-2010-0624Gnu cpio memory buffer overflow vulnerabilityHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…EPSS 4.7%6.8CVE-2007-4131Gnu tar vulnerabilityDirectory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…EPSS 2.7%6.2CVE-2023-39804Gnu tar vulnerabilityIn GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.EPSS 0.28%5.5CVE-2026-5704Gnu tar unrestricted file upload vulnerabilityA flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…EPSS 0.40%5.5CVE-2022-48303Gnu tar out-of-bounds read vulnerabilityGNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2016-6321), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.