Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-5704

Опубликовано: 06 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5

Описание

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

РелизСтатусПримечание
devel

pending

1.35+dfsg-4ubuntu2
esm-infra-legacy/trusty

released

1.27.1-1ubuntu0.1+esm7
esm-infra-legacy/xenial

released

1.28-2.1ubuntu0.2+esm6
esm-infra/bionic

released

1.29b-2ubuntu0.4+esm4
esm-infra/focal

released

1.30+dfsg-7ubuntu0.20.04.4+esm3
esm-infra/xenial

ignored

end of ESM support, was deferred [2026-04-23]
jammy

released

1.34+dfsg-1ubuntu0.1.22.04.6
noble

released

1.35+dfsg-3ubuntu0.4
questing

ignored

end of life, was needs-triage
resolute

released

1.35+dfsg-4ubuntu0.4

Показывать по

EPSS

Процентиль: 30%
0.00372
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
nvd
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
debian
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerab ...

suse-cvrf
около 1 месяца назад

Security update for tar

CVSS3: 5
github
4 месяца назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

EPSS

Процентиль: 30%
0.00372
Низкий

5 Medium

CVSS3