Vulnerability Name:

CVE-2006-6097 (CCN-30472)

Assigned:2006-11-21
Published:2006-11-21
Updated:2018-10-17
Summary:GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P)
3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
2.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: SGI
Type: UNKNOWN
20061202-01-P

Source: CCN
Type: Full-Disclosure Mailing List, Tue Nov 21 2006 - 16:39:12 CS
GNU tar directory traversal

Source: MITRE
Type: CNA
CVE-2006-6097

Source: CCN
Type: Mac OS X 10.4.9 and Security Update 2007-003
About the security content of Mac OS X 10.4.9 and Security Update 2007-003

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=305214

Source: CONFIRM
Type: UNKNOWN
http://kb.vmware.com/KanisaPlatform/Publishing/817/2240267_f.SAL_Public.html

Source: APPLE
Type: UNKNOWN
APPLE-SA-2007-03-13

Source: FULLDISC
Type: Exploit
20061121 GNU tar directory traversal

Source: CCN
Type: RHSA-2006-0749
Moderate: tar security update

Source: REDHAT
Type: UNKNOWN
RHSA-2006:0749

Source: CCN
Type: SA23115
GNU tar "GNUTYPES_NAMES" Record Type Security Issue

Source: SECUNIA
Type: UNKNOWN
23115

Source: SECUNIA
Type: UNKNOWN
23117

Source: SECUNIA
Type: UNKNOWN
23142

Source: SECUNIA
Type: UNKNOWN
23146

Source: SECUNIA
Type: UNKNOWN
23163

Source: SECUNIA
Type: UNKNOWN
23173

Source: SECUNIA
Type: UNKNOWN
23198

Source: SECUNIA
Type: UNKNOWN
23209

Source: SECUNIA
Type: UNKNOWN
23314

Source: SECUNIA
Type: UNKNOWN
23443

Source: SECUNIA
Type: UNKNOWN
23514

Source: CCN
Type: SA23911
Avaya Products tar "GNUTYPES_NAMES" Record Type Security Issue

Source: SECUNIA
Type: UNKNOWN
23911

Source: CCN
Type: SA24479
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
24479

Source: CCN
Type: SA24636
VMware ESX Server Multiple Security Updates

Source: SECUNIA
Type: UNKNOWN
24636

Source: CCN
Type: FreeBSD-SA-06:26.gtar
gtar name mangling symlink vulnerability

Source: FREEBSD
Type: UNKNOWN
FreeBSD-SA-06:26

Source: GENTOO
Type: UNKNOWN
GLSA-200612-10

Source: SREASON
Type: UNKNOWN
1918

Source: CCN
Type: SECTRACK ID: 1017423
GNU tar GNUTYPE_NAMES Record Directory Traversal Flaw May Let Remote Users Overwrite Arbitrary Files

Source: SECTRACK
Type: UNKNOWN
1017423

Source: SLACKWARE
Type: UNKNOWN
SSA:2006-335-01

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2007-015.htm

Source: CCN
Type: ASA-2007-015
tar security update (RHSA-2006-0749)

Source: CCN
Type: Apple Mac OS X Web site
Apple - Mac OS X

Source: DEBIAN
Type: UNKNOWN
DSA-1223

Source: DEBIAN
Type: DSA-1223
tar -- input validation error

Source: CCN
Type: GLSA-200612-10
Tar: Directory traversal vulnerability

Source: CCN
Type: GNU Tar Web site
Tar - GNU Project - Free Software Foundation (FSF)

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2006:219

Source: CCN
Type: OpenPKG-SA-2006.038
GNU tar

Source: OPENPKG
Type: UNKNOWN
OpenPKG-SA-2006.038

Source: BUGTRAQ
Type: UNKNOWN
20061201 rPSA-2006-0222-1 tar

Source: BUGTRAQ
Type: UNKNOWN
20070330 VMSA-2007-0002 VMware ESX security updates

Source: BID
Type: Exploit
21235

Source: CCN
Type: BID-21235
GNU Tar GNUTYPE_NAMES Remote Directory Traversal Vulnerability

Source: TRUSTIX
Type: UNKNOWN
2006-0068

Source: CCN
Type: TLSA-2006-42
Symlink attack in tar

Source: CCN
Type: USN-385-1
tar vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-385-1

Source: CERT
Type: US Government Resource
TA07-072A

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/support/esx25/doc/esx-254-200702-patch.html

Source: VUPEN
Type: UNKNOWN
ADV-2006-4717

Source: VUPEN
Type: UNKNOWN
ADV-2006-5102

Source: VUPEN
Type: UNKNOWN
ADV-2007-0930

Source: VUPEN
Type: UNKNOWN
ADV-2007-1171

Source: MISC
Type: Exploit
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=216937

Source: XF
Type: UNKNOWN
gnutar-gnutypenames-symlink(30472)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-821

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10963

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:tar:1.15.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:tar:1.16:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:tar:1.15.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:tar:1.16:*:*:*:*:*:*:*
  • AND
  • cpe:/o:freebsd:freebsd:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.0:alpha:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.0:alpha:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.0:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.1:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.2:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.3:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.4:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.5:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.6:-:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:current:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.7:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.8:-:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.1:-:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.2:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.9:-:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.2.1:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.1:alpha:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.10:-:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.3:-:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:5.4:-:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2006:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2006::x86-64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.11:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.6.2:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20066097
    V
    CVE-2006-6097
    2022-06-30
    oval:org.opensuse.security:def:113480
    P
    tar-1.34-2.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26224
    P
    Security update for libvirt (Important)
    2022-01-05
    oval:org.opensuse.security:def:32287
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:31753
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:31722
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:31330
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:32228
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:31311
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:32226
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:26171
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:31300
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:42239
    P
    Security update for the Linux Kernel (Important)
    2021-11-16
    oval:org.opensuse.security:def:31299
    P
    Security update for qemu (Important)
    2021-11-10
    oval:org.opensuse.security:def:26158
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:26142
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:106877
    P
    tar-1.34-2.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:33008
    P
    Security update for ghostscript (Critical)
    2021-09-21
    oval:org.opensuse.security:def:26114
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:32177
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:31666
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:26100
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:32121
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:32119
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:31198
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:36308
    P
    tar-1.26-1.2.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42715
    P
    tar-1.26-1.2.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32075
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32084
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:31609
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:32265
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:26199
    P
    Security update for ImageMagick (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:31729
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:32969
    P
    Security update for python36 (Important)
    2021-02-01
    oval:org.opensuse.security:def:32141
    P
    Security update for MozillaFirefox (Important)
    2021-01-29
    oval:org.opensuse.security:def:26061
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:31566
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:25971
    P
    Security update for fontforge (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35644
    P
    tar-1.20-23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42051
    P
    tar-1.20-23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35832
    P
    tar-1.26-1.2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36045
    P
    tar-1.26-1.2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42452
    P
    tar-1.26-1.2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25394
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25724
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26536
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27271
    P
    ppc64-diag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25595
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25879
    P
    Security update for pidgin-otr (Important)
    2020-12-01
    oval:org.opensuse.security:def:31932
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25857
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26434
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32489
    P
    apache2-mod_php5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33232
    P
    perl-spamassassin on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31512
    P
    Recommended update for python 2.7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31821
    P
    Security update for avahi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32440
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26609
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31774
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31992
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32384
    P
    Security update for tiff (Low)
    2020-12-01
    oval:org.opensuse.security:def:25195
    P
    Security update for audiofile (Low)
    2020-12-01
    oval:org.opensuse.security:def:25399
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:25772
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26326
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25458
    P
    Security update for sqlite3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25808
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26575
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27306
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25606
    P
    Security update for libjpeg-turbo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25936
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31827
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:32570
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25858
    P
    Security update for util-linux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26487
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31112
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31385
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32528
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33271
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31523
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31878
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25913
    P
    Security update for tcpdump, libpcap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26644
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31775
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25874
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26796
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25196
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25480
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25825
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26370
    P
    Security update for mbedtls (Important)
    2020-12-01
    oval:org.opensuse.security:def:25382
    P
    Security update for squid (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25586
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:25959
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26589
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25670
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26020
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31866
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32609
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25869
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32014
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32757
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31113
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31422
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31778
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32331
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31517
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:31909
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32550
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31597
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31965
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25927
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31786
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26831
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25207
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25537
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26273
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27008
    P
    pango on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25383
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25667
    P
    Security update for u-boot (Important)
    2020-12-01
    oval:org.opensuse.security:def:26012
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26633
    P
    python on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25594
    P
    Security update for targetcli-fb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25798
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31888
    P
    Security update for evince (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25933
    P
    Security update for gstreamer-0_10-plugins-good (Important)
    2020-12-01
    oval:org.opensuse.security:def:26283
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32053
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32796
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31124
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31479
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32594
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31511
    P
    Security update for python27-urllib3, python27-boto3, python27-botocore, python27-s3transfer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31860
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25271
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25621
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26312
    P
    Security update for dnsmasq (Important)
    2020-12-01
    oval:org.opensuse.security:def:27043
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:10963
    V
    GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
    2013-04-29
    oval:com.redhat.rhsa:def:20060749
    P
    RHSA-2006:0749: tar security update (Moderate)
    2006-12-19
    oval:org.debian:def:1223
    V
    input validation error
    2006-12-01
    BACK
    gnu tar 1.15.1
    gnu tar 1.16
    gnu tar 1.15.1
    gnu tar 1.16
    freebsd freebsd 4.0
    freebsd freebsd 4.0 alpha
    freebsd freebsd 5.0 alpha
    freebsd freebsd 5.0 -
    freebsd freebsd 4.1.1
    freebsd freebsd 4.1
    freebsd freebsd 4.2
    freebsd freebsd 4.3 -
    freebsd freebsd 4.4 -
    freebsd freebsd 4.5 -
    freebsd freebsd 4.6 -
    openpkg openpkg current
    gentoo linux *
    freebsd freebsd 4.7 -
    freebsd freebsd 4.8 -
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    freebsd freebsd 5.1 -
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    freebsd freebsd 5.2 -
    freebsd freebsd 4.9 -
    redhat enterprise linux 3
    freebsd freebsd 5.2.1 -
    freebsd freebsd 5.1 alpha
    freebsd freebsd 4.10 -
    mandrakesoft mandrake linux corporate server 3.0
    redhat enterprise linux 4
    redhat enterprise linux 4
    freebsd freebsd 5.3 -
    redhat enterprise linux 4
    redhat enterprise linux 4
    debian debian linux 3.1
    mandrakesoft mandrake multi network firewall 2.0
    freebsd freebsd 5.4 -
    redhat linux advanced workstation 2.1
    mandrakesoft mandrake linux 2006
    canonical ubuntu 6.06
    mandrakesoft mandrake linux 2006
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    turbolinux turbolinux fuji
    freebsd freebsd 4.11 -
    freebsd freebsd 4.6.2 -