Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5704

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 5

Описание

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Меры по смягчению последствий

To mitigate this issue, avoid extracting archives from untrusted sources. If processing untrusted archives is necessary, do so within a sandboxed environment to limit potential impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tarAffected
Red Hat Enterprise Linux 6tarFix deferred
Red Hat Enterprise Linux 7tarFix deferred
Red Hat Enterprise Linux 8tarFix deferred
Red Hat Enterprise Linux 9tarAffected
Red Hat Hardened ImagestarAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-434
https://bugzilla.redhat.com/show_bug.cgi?id=2455360tar: tar: Hidden file injection via crafted archives

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
nvd
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
debian
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerab ...

suse-cvrf
около 1 месяца назад

Security update for tar

CVSS3: 5
github
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

5 Medium

CVSS3