Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-0842

Опубликовано: 22 фев. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-0842: tar security update (MODERATE)

[1.30-6.1]

  • Fix CVE-2022-48303
  • Resolves: CVE-2022-48303

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

tar

1.30-6.el8_7.1

Oracle Linux x86_64

tar

1.30-6.el8_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
redhat
почти 4 года назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
nvd
около 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 5.5
debian
около 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in ...