Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:minitar:archive-tar-minitar:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "0.5.2"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:a:minitar:minitar:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "0.5.4"
}
],
"source": "CPE_FIELD"
}
]
}