Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader

CVE-2025-45582 - tar: Tar path traversal

Hi Team,

 

According to GitHub, a recent vulnerability (CVE-2025-45582) has been reported, classified as medium severity. Although the impact is not severe on its own.

As vulnerability scanners begin to detect this issue, it's likely that our systems will be flagged soon. To mitigate potential disruptions, I recommend checking with Checkpoint's support team to determine if they plan to release any patches or updates for this vulnerability in the near future.

https://www.cve.org/CVERecord?id=CVE-2025-45582

https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md

https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

 

Note if not already you can subscribe to updates regarding IPS protections here:

https://advisories.checkpoint.com/defense/advisories/public/sdnews/

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

It seems like this would require explicit actions by a trusted administrative user using maliciously crafted files to exploit.
Not to say this won't get fixed, but it's likely going to be done as part of the normal JHF process.
For a formal response, contact TAC. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events