CVE-2005-2541

SOURCE - nist

Summary

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

EPSS Score: 0.00634 (0.790)

Common Weakness Enumeration (CWE)

SOURCE - nist

debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/tardebdebian12>=1.34+dfsg-1.2+deb12u1Not yet available
debian/tardebdebian13>=1.35+dfsg-3Not yet available
debian/tardebdebian10>=1.30+dfsg-6Not yet available
debian/tardebdebianunstable>=1.35+dfsg-3Not yet available
debian/tardebdebian11>=1.34+dfsg-1+deb11u1Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

10


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

10high

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.0


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7medium