Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9923

Опубликовано: 02 янв. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

Отчет

This issue is classified with a low severity primarily because untrusted tar files are not typically extracted with the root user, limiting the impact of this issue. Additionally, this NULL pointer dereference is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with tar. Furthermore, tar does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tarNot affected
Red Hat Enterprise Linux 6tarWill not fix
Red Hat Enterprise Linux 7tarFix deferred
Red Hat Enterprise Linux 8tarFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1691764tar: null-pointer dereference in pax_decode_header in sparse.c

EPSS

Процентиль: 60%
0.004
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

CVSS3: 7.5
nvd
почти 7 лет назад

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

CVSS3: 7.5
debian
почти 7 лет назад

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointe ...

CVSS3: 7.5
github
больше 3 лет назад

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость архиватора GNU Tar, связанная с недостаточным выделением памяти для операции, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 60%
0.004
Низкий

3.3 Low

CVSS3