Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk. | |
| First Time appeared |
Gnupg
Gnupg gnupg |
|
| Weaknesses | CWE-61 | |
| CPEs | cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnupg
Gnupg gnupg |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-05T19:09:30.980Z
Reserved: 2026-10-05T18:53:09.023Z
Link: CVE-2026-105712
Updated: 2026-10-05T19:09:26.691Z
Status : Received
Published: 2026-10-05T19:17:19.527
Modified: 2026-10-05T20:17:20.460
Link: CVE-2026-105712
No data.
OpenCVE Enrichment
No data.