Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-48303

Опубликовано: 30 янв. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

РелизСтатусПримечание
bionic

released

1.29b-2ubuntu0.4
devel

released

1.34+dfsg-1.2ubuntu1
esm-infra-legacy/trusty

not-affected

1.27.1-1ubuntu0.1+esm3
esm-infra/bionic

not-affected

1.29b-2ubuntu0.4
esm-infra/focal

not-affected

1.30+dfsg-7ubuntu0.20.04.3
esm-infra/xenial

released

1.28-2.1ubuntu0.2+esm2
focal

released

1.30+dfsg-7ubuntu0.20.04.3
jammy

released

1.34+dfsg-1ubuntu0.1.22.04.1
kinetic

released

1.34+dfsg-1ubuntu0.1.22.10.1
lunar

released

1.34+dfsg-1.2ubuntu0.1

Показывать по

EPSS

Процентиль: 7%
0.00032
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
nvd
больше 2 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVSS3: 5.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
больше 2 лет назад

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in ...

suse-cvrf
больше 2 лет назад

Security update for tar

EPSS

Процентиль: 7%
0.00032
Низкий

5.5 Medium

CVSS3