CVE-2005-2541

ADVISORY - debian

Summary

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.


This is intended behaviour, after all tar is an archiving tool and you need to give -p as a command line flag

EPSS Score: 0.02806 (0.854)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Debian

CREATED

UPDATED

ADVISORY IDCVE-2005-2541
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/tardebdebian12>=1.34+dfsg-1.2+deb12u1Not yet available
debian/tardebdebian13>=1.35+dfsg-3.1Not yet available
debian/tardebdebian11>=1.34+dfsg-1+deb11u1Not yet available
debian/tardebdebianunstable>=1.35+dfsg-3.1Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2005-2541
EXPLOITABILITY SCORE

10

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

10high

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2005-2541
EXPLOITABILITY SCORE

1.0

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7medium