Gentoo Linux Security Advisory GLSA 200710-23 – Robert Buchholz of the Gentoo Security team discovered a directory traversal vulnerability in the has_dotdot() function which does not identify //.. (slash slash dot dot) sequences in file names inside tar files. Versions less than 1.5_alpha84 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60329/glsa-200710-23.txt
Source: https://packetstormsecurity.com/files/60329/Gentoo-Linux-Security-Advisory-200710-23.html

