Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-48303

Опубликовано: 30 янв. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

РелизСтатусПримечание
bionic

released

1.29b-2ubuntu0.4
devel

released

1.34+dfsg-1.2ubuntu1
esm-infra-legacy/trusty

released

1.27.1-1ubuntu0.1+esm3
esm-infra/bionic

released

1.29b-2ubuntu0.4
esm-infra/focal

released

1.30+dfsg-7ubuntu0.20.04.3
esm-infra/xenial

released

1.28-2.1ubuntu0.2+esm2
focal

released

1.30+dfsg-7ubuntu0.20.04.3
jammy

released

1.34+dfsg-1ubuntu0.1.22.04.1
kinetic

released

1.34+dfsg-1ubuntu0.1.22.10.1
lunar

released

1.34+dfsg-1.2ubuntu0.1

Показывать по

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
nvd
почти 3 года назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 3 года назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in ...

suse-cvrf
почти 3 года назад

Security update for tar

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3