Vulnerability Name:

CVE-2007-4134 (CCN-36324)

Assigned:2007-08-21
Published:2007-08-21
Updated:2018-10-15
Summary:Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-22
Vulnerability Consequences:Gain Access
References:Source: CONFIRM
Type: UNKNOWN
ftp://ftp.berlios.de/pub/star/alpha/AN-1.5a84

Source: SGI
Type: UNKNOWN
20070901-01-P

Source: CCN
Type: Star Web site
Star a very fast and Posix 1003.1 compliant tar archiver for UNIX

Source: MITRE
Type: CNA
CVE-2007-4134

Source: CCN
Type: RHSA-2007-0873
Moderate: star security update

Source: CCN
Type: SA26626
Star Directory Traversal Vulnerability

Source: SECUNIA
Type: UNKNOWN
26626

Source: SECUNIA
Type: UNKNOWN
26672

Source: SECUNIA
Type: UNKNOWN
26673

Source: SECUNIA
Type: UNKNOWN
26857

Source: SECUNIA
Type: UNKNOWN
27318

Source: CCN
Type: SA27544
Avaya Products Star Directory Traversal Vulnerability

Source: SECUNIA
Type: UNKNOWN
27544

Source: CCN
Type: SECTRACK ID: 1018646
Star `//` Pathname Validation Flaw Lets Remote Users Create/Ovewrite Files

Source: SECTRACK
Type: UNKNOWN
1018646

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2007-414.htm

Source: CCN
Type: ASA-2007-414
star security update (RHSA-2007-0873)

Source: CCN
Type: GLSA-200710-23
Star: Directory traversal vulnerability

Source: GENTOO
Type: UNKNOWN
GLSA-200710-23

Source: FEDORA
Type: Patch
FEDORA-2007-1852

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0873

Source: BUGTRAQ
Type: UNKNOWN
20070907 FLEA-2007-0051-1 star

Source: CCN
Type: Gentoo Bugzilla Bug 189690
app-arch/star: Directory traversal vulnerability (CVE-2007-4131)

Source: CONFIRM
Type: Patch
https://bugs.gentoo.org/show_bug.cgi?id=189690

Source: XF
Type: UNKNOWN
star-filename-directory-traversal(36324)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1669

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:11098

Vulnerable Configuration:Configuration 1:
  • cpe:/o:redhat:fedora:7:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20074134
    V
    CVE-2007-4134
    2022-05-20
    oval:org.opensuse.security:def:26188
    P
    Security update for gegl (Important)
    2021-12-28
    oval:org.opensuse.security:def:31325
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31719
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:31717
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:31303
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:32217
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:32216
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:26161
    P
    Security update for samba (Important)
    2021-11-10
    oval:org.opensuse.security:def:42231
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:26150
    P
    Security update for util-linux (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:31291
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:31292
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:26131
    P
    Security update for xen (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:32167
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:26106
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:31658
    P
    Security update for the Linux Kernel (Important)
    2021-07-22
    oval:org.opensuse.security:def:26092
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:32959
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:32130
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:31193
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:36297
    P
    star-1.5final-28.23.25.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42704
    P
    star-1.5final-28.23.25.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32111
    P
    Security update for MozillaFirefox (Important)
    2021-06-08
    oval:org.opensuse.security:def:26053
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:26050
    P
    Security update for python3 (Important)
    2021-05-17
    oval:org.opensuse.security:def:32073
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:32067
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:26214
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:32277
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31745
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:32255
    P
    Security update for the Linux Kernel (Important)
    2021-02-12
    oval:org.opensuse.security:def:32998
    P
    Security update for python-urllib3 (Moderate)
    2021-02-03
    oval:org.opensuse.security:def:32006
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:31561
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:42442
    P
    star-1.5final-28.23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35639
    P
    star-1.5final-28.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42046
    P
    star-1.5final-28.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35824
    P
    star-1.5final-28.21.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36035
    P
    star-1.5final-28.23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25966
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:25386
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25716
    P
    Security update for librsvg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26263
    P
    Security update for libEMF (Important)
    2020-12-01
    oval:org.opensuse.security:def:32565
    P
    librpcsecgss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25585
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25869
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31927
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25846
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26423
    P
    Security update for opencv (Important)
    2020-12-01
    oval:org.opensuse.security:def:32045
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33260
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26639
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31502
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31811
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26788
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31763
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31981
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32373
    P
    Security update for tcpdump (Important)
    2020-12-01
    oval:org.opensuse.security:def:25190
    P
    Security update for virglrenderer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25394
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25767
    P
    Security update for DirectFB (Important)
    2020-12-01
    oval:org.opensuse.security:def:26316
    P
    Recommended update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25450
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25800
    P
    Security update for polkit (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26302
    P
    Security update for python-PyYAML (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32604
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25596
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25926
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26525
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32749
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25847
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26476
    P
    Security update for nextcloud (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32321
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31107
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31377
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31513
    P
    Security update for quagga
    2020-12-01
    oval:org.opensuse.security:def:31868
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32478
    P
    Security update for zsh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26823
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31764
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLE and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:32429
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26998
    P
    ofed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25191
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25475
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:25820
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26360
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25374
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25578
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:25951
    P
    Security update for pcsc-lite (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26578
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25660
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:26010
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:26564
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32788
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25858
    P
    Security update for util-linux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31822
    P
    Security update for axis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31108
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31417
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31773
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32583
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31509
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31901
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32539
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31587
    P
    Security update for tcpdump (Important)
    2020-12-01
    oval:org.opensuse.security:def:31955
    P
    Security update for gstreamer-0_10-plugins-good (Important)
    2020-12-01
    oval:org.opensuse.security:def:32517
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31775
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25908
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:27033
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25202
    P
    Security update for libgxps (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25532
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27260
    P
    pango on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25375
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25659
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26004
    P
    Security update for shotwell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26622
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25584
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25788
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31883
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25922
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26272
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31861
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:31119
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:31474
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33221
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31601
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31957
    P
    Security update for gdk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26604
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31501
    P
    Security update for python-pycrypto (Important)
    2020-12-01
    oval:org.opensuse.security:def:31849
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:25266
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25616
    P
    Security update for less (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27295
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:22697
    P
    ELSA-2007:0873: star security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:11098
    V
    Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
    2013-04-29
    oval:com.redhat.rhsa:def:20070873
    P
    RHSA-2007:0873: star security update (Moderate)
    2007-09-04
    BACK
    redhat fedora 7