CVE-2013-4420: Feep Libtar

Medium severity, CVSS 5.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

Affected products

  • Feep Libtar: up to and including 1.2.20; version 1.2.11 only; version 1.2.13 only; version 1.2.14 only; version 1.2.15 only; version 1.2.16 only; …

Published 2014-02-20. Last modified 2026-06-16.