CVE-2006-0300

13 documents9 sources
Severity
5.1MEDIUM
EPSS
18.8%
top 4.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Latest updateMay 1

Description

Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

Debiantar< 1.15.1-3+3
NVDgnu/tar5 versions+4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v2qx-rhmh-m93w: Buffer overflow in tar 12022-05-01
CVEList
CVE-2006-0300: Buffer overflow in tar 12006-02-24
OSV
CVE-2006-0300: Buffer overflow in tar 12006-02-24

💥Exploits & PoCs

2
Exploit-DB
Apple iCal 3.0.1 - 'COUNT' Integer Overflow2008-04-21
Exploit-DB
Apple iCal 3.0.1 - 'TRIGGER' Denial of Service2008-04-21

📋Vendor Advisories

3
Ubuntu
tar vulnerability2006-02-23
Debian
CVE-2006-0300: dpkg - Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to ca...2006
Red Hat
security flaw2005-06-17

💬Community

4
Bugzilla
CVE-2006-0300 security flaw2018-08-16
Bugzilla
Multiple tar issues (CVE-2005-1918, CVE-2006-0300)2006-03-02
Bugzilla
CVE-2006-0300 GNU tar heap overlfow bug2006-02-16
Bugzilla
CVE-2006-0300 GNU tar heap overlfow bug2006-02-16