{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu16.04els/vex/2025/cve-2025-45582-els_os-ubuntu16_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-02T02:16:31Z",
      "generator": {
        "date": "2026-08-02T02:16:30Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-45582-ELS_OS-UBUNTU16.04ELS",
      "initial_release_date": "2025-07-11T17:15:00Z",
      "revision_history": [
        {
          "date": "2025-07-11T17:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T15:31:42Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-31T19:04:02Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-08-02T02:16:31Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2025-45582"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/tar-scripts@1.28-2.1ubuntu0.2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/tar@1.28-2.1ubuntu0.2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 16.04",
                "product": {
                  "name": "Ubuntu 16.04",
                  "product_id": "Ubuntu-16",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar-scripts@1.28-2.1ubuntu0.2%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar-scripts@1.28-2.1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar@1.28-2.1ubuntu0.2%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar@1.28-2.1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-45582",
      "cwe": {
        "id": "CWE-24",
        "name": "Path Traversal: '../filedir'"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-45582"
        },
        {
          "category": "external",
          "summary": "https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md",
          "url": "https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md"
        },
        {
          "category": "external",
          "summary": "https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html",
          "url": "https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html"
        },
        {
          "category": "external",
          "summary": "https://www.gnu.org/software/tar/",
          "url": "https://www.gnu.org/software/tar/"
        },
        {
          "category": "external",
          "summary": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html",
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html"
        },
        {
          "category": "external",
          "summary": "https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html",
          "url": "https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/11/01/6",
          "url": "http://www.openwall.com/lists/oss-security/2025/11/01/6"
        }
      ],
      "release_date": "2025-07-11T17:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-31T18:39:22.336698Z",
          "details": "CVE-2025-45582 is high-complexity to exploit because it requires two separate extractions of attacker-supplied tar archives into the same destination directory, leaving a symlink from the first run that the second run then leverages. The result is limited to overwriting files reachable by the extracting user’s permissions (no direct code execution or privilege escalation), and it only materializes in workflows that automatically and repeatedly extract untrusted archives into a shared directory without cleanup. Enterprise VM/server deployments that extract into isolated or empty build/install paths do not satisfy these preconditions, so this can be safely deprioritized.",
          "product_ids": [
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}