CVE-2016-6321 is a directory traversal vulnerability affecting GNU tar versions 1.14 through 1.29. This flaw, dubbed POINTYFEATHER, allows remote attackers to bypass intended security mechanisms and write to arbitrary files due to improper sanitization of file names during extraction. With a CVSS score of 7.5 (HIGH), it presents a significant risk as it can be exploited remotely with low complexity and no user interaction, leading to high integrity impact. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14CPE matchmatch criteria | cpe:2.3:a:gnu:tar:1.14:*:*:*:*:*:*:* | ||
1.15CPE matchmatch criteria | cpe:2.3:a:gnu:tar:1.15:*:*:*:*:*:*:* | ||
1.15.1CPE matchmatch criteria | cpe:2.3:a:gnu:tar:1.15.1:*:*:*:*:*:*:* | ||
1.15.90CPE matchmatch criteria | cpe:2.3:a:gnu:tar:1.15.90:*:*:*:*:*:*:* | ||
1.15.91CPE matchmatch criteria | cpe:2.3:a:gnu:tar:1.15.91:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.