CVE-2005-1918

Source
https://cve.org/CVERecord?id=CVE-2005-1918
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2005-1918.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2005-1918
Downstream
Related
Published
2005-12-31T05:00:00Z
Modified
2026-02-04T11:23:10.974196Z
Summary
[none]
Details

The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".

References

Affected packages