Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"vendor_product": "minitar:archive-tar-minitar",
"extracted_events": [
{
"last_affected": "0.5.2"
}
],
"cpes": [
"cpe:2.3:a:minitar:archive-tar-minitar:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_FIELD",
"vendor_product": "minitar:minitar",
"extracted_events": [
{
"last_affected": "0.5.4"
}
],
"cpes": [
"cpe:2.3:a:minitar:minitar:*:*:*:*:*:*:*:*"
]
}
]
}