GNU Tar 1.27

CPE Details

GNU Tar 1.27
1.27
2019-04-17
11h48 +00:00
2019-04-17
11h48 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnu:tar:1.27:*:*:*:*:*:*:*

Informations

Vendor

gnu

Product

tar

Version

1.27

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-48303 2023-01-30 00h00 +00:00 GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
5.5
Medium
CVE-2021-20193 2021-03-26 15h41 +00:00 A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
3.3
Low
CVE-2019-9923 2019-03-22 06h06 +00:00 pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
7.5
High
CVE-2018-20482 2018-12-26 17h00 +00:00 GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
4.7
Medium
CVE-2016-6321 2016-12-09 21h00 +00:00 Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
7.5
High