GNU tar 1.29 Extract Pathname Bypass

The GNU tar archiver can be tricked into extracting files and directories in the given destination, regardless of the path name(s) specified on the command line. Versions 1.14 through 1.29 are affected.

Leave a Reply