Описание
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-39804
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079
- https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4
- https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723
- https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html
Связанные уязвимости
CVSS3: 6.2
ubuntu
больше 1 года назад
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS3: 3.3
redhat
почти 2 года назад
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS3: 6.2
nvd
больше 1 года назад
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS3: 6.2
debian
больше 1 года назад
In GNU tar before 1.35, mishandled extension attributes in a PAX archi ...