Debian Security Advisory 1438-1 – Several vulnerabilities have been discovered in GNU Tar. A directory traversal vulnerability enables attackers using specially crafted archives to extract contents outside the directory tree created by tar. A stack-based buffer overflow in the file name checking code may lead to arbitrary code execution when processing maliciously crafted archives.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/62158/dsa-1438-1.txt
Source: https://packetstormsecurity.com/files/62158/Debian-Linux-Security-Advisory-1438-1.html

