Количество 5
Количество 5
CVE-2025-62518
astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.
CVE-2025-62518
astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.
CVE-2025-62518
astral-tokio-tar Vulnerable to PAX Header Desynchronization
CVE-2025-62518
astral-tokio-tar is a tar archive reading/writing library for async Ru ...
GHSA-j5gw-2vrg-8fgx
astral-tokio-tar Vulnerable to PAX Header Desynchronization
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-2025-62518 astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.  | CVSS3: 8.1  | 0% Низкий | 14 дней назад | |
CVE-2025-62518 astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.  | CVSS3: 8.1  | 0% Низкий | 14 дней назад | |
CVE-2025-62518 astral-tokio-tar Vulnerable to PAX Header Desynchronization  | 0% Низкий | 10 дней назад | ||
CVE-2025-62518 astral-tokio-tar is a tar archive reading/writing library for async Ru ...  | CVSS3: 8.1  | 0% Низкий | 14 дней назад | |
GHSA-j5gw-2vrg-8fgx astral-tokio-tar Vulnerable to PAX Header Desynchronization  | CVSS3: 8.1  | 0% Низкий | 14 дней назад | 
Уязвимостей на страницу