Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
{ "versions": [ { "introduced": "0" }, { "fixed": "0.6" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10173.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "0.5.2" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "0.5.4" } ] } ]