yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2013-4420
Component Overview
Vulnerability Overview
Name
CVE-2013-4420
Source
NVD (
link
)
Debian (
link
)
Description
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
CWEs
CWE-22
Published Date
Feb 20, 2014
Updated Date
Jun 16, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
libtar
Exploitable
Vulnerability Rating
#
5.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
libtar
yocto
kirkstone
1.2.20
Exploitable
libtar
yocto
master
1.2.20
Exploitable