Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39804

Опубликовано: 11 дек. 2023
Источник: redhat
CVSS3: 3.3

Описание

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service.

Отчет

To exploit this flaw, an attacker needs to trick a user into processing a malicious archive, causing only an application crash. For these reasons, this flaw was rated with a low, and not moderate, severity.

Меры по смягчению последствий

Do not process untrusted tar archives.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tarOut of support scope
Red Hat Enterprise Linux 7tarFix deferred
Red Hat Enterprise Linux 8tarFix deferred
Red Hat Enterprise Linux 9tarFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2254067tar: Incorrectly handled extension attributes in PAX archives can lead to a crash

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 1 года назад

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

CVSS3: 6.2
nvd
около 1 года назад

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

CVSS3: 6.2
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 6.2
debian
около 1 года назад

In GNU tar before 1.35, mishandled extension attributes in a PAX archi ...

suse-cvrf
больше 1 года назад

Security update for tar

3.3 Low

CVSS3