Search/CVE-2025-45582
CVE — Medium

CVE-2025-45582

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can…

CVSS v3.1
4.1 MEDIUM
EPSS
0.45%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 11, 2026
0.02pp
0.43% → 0.45% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityNONE
IntegrityLOW
AvailabilityLOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
Jul 11, 2025
Disclosure — published as a CVE record. · last revised by NVD Nov 2, 2025