#VU105975 External Control of File Name or Path in archiver - CVE-2024-0406
Published: March 24, 2025 / Updated: April 11, 2025
archiver
mholt (Matt Holt)
Description
The vulnerability allows a remote attacker to overwrite arbitrary files on the system.
The vulnerability exists due to application allows an attacker to control path of the files when extracting data from a .tar archive. A remote attacker can pass specially crafted archive to the application and overwrite arbitrary files on the system.