Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-0842

Опубликовано: 22 фев. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-0842: tar security update (MODERATE)

[1.30-6.1]

  • Fix CVE-2022-48303
  • Resolves: CVE-2022-48303

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

tar

1.30-6.el8_7.1

Oracle Linux x86_64

tar

1.30-6.el8_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
redhat
больше 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
nvd
больше 2 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
больше 2 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in ...