{"id":"CVE-2005-1918","details":"The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an \"incorrect optimization\" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving \"/../\" sequences with a leading \"/\".","modified":"2026-01-27T04:06:01.597424Z","published":"2005-12-31T05:00:00Z","withdrawn":"2026-01-27T04:06:01.597424Z","related":["openSUSE-SU-2024:11422-1"],"references":[{"type":"ADVISORY","url":"ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc"},{"type":"FIX","url":"http://secunia.com/advisories/18988"},{"type":"ADVISORY","url":"http://secunia.com/advisories/19130"},{"type":"FIX","url":"http://secunia.com/advisories/19183"},{"type":"ADVISORY","url":"http://secunia.com/advisories/20397"},{"type":"ADVISORY","url":"http://www.novell.com/linux/security/advisories/2006_05_sr.html"},{"type":"FIX","url":"http://www.redhat.com/support/errata/RHSA-2006-0195.html"},{"type":"FIX","url":"http://securitytracker.com/id?1015655"},{"type":"FIX","url":"http://www.securityfocus.com/bid/5834"},{"type":"REPORT","url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=140589"},{"type":"WEB","url":"http://support.avaya.com/elmodocs2/security/ASA-2006-110.htm"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/430297/100/0/threaded"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9946"}],"schema_version":"1.7.3"}