GNU tar 1.29 Extract Pathname Bypass
Posted by deepcore on October 28, 2016 – 11:24 pm
The GNU tar archiver can be tricked into extracting files and directories in the given destination, regardless of the path name(s) specified on the command line. Versions 1.14 through 1.29 are affected.
Post a reply
You must be logged in to post a comment.