CVE-2007-4476
published 2007-09-05CVE-2007-4476: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
14.90%
96.3th percentile
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cpio | < cpio 2.9-5 (bookworm) | cpio 2.9-5 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tar | < cpio 2.9-5 (bookworm) | cpio 2.9-5 (bookworm) |
| gnu | cpio | >= 0 < 2.9-5 | 2.9-5 |
| gnu | cpio | >= 0 < 2.9-5 | 2.9-5 |
| gnu | cpio | >= 0 < 2.9-5 | 2.9-5 |
| gnu | cpio | >= 0 < 2.9-5 | 2.9-5 |
| gnu | tar | < 1.19 | 1.19 |
| gnu | tar | >= 0 < 1.18-1 | 1.18-1 |
| gnu | tar | >= 0 < 1.18-1 | 1.18-1 |
| gnu | tar | >= 0 < 1.18-1 | 1.18-1 |
| gnu | tar | >= 0 < 1.18-1 | 1.18-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc9f-9qmm-9663: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack
ghsa_unreviewed·2022-05-01
CVE-2007-4476 [HIGH] CWE-119 GHSA-qc9f-9qmm-9663: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
OSV
CVE-2007-4476: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack
osv·2007-09-05·CVSS 7.5
CVE-2007-4476 [HIGH] CVE-2007-4476: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Ubuntu
tar vulnerability
vendor_ubuntu·2009-01-15
CVE-2007-4476 tar vulnerability
Title: tar vulnerability
Summary: tar vulnerability
Dmitry V. Levin discovered a buffer overflow in tar. If a user or automated
system were tricked into opening a specially crafted tar file, an attacker
could crash tar or possibly execute arbitrary code with the privileges of the
user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
cpio vulnerability
vendor_ubuntu·2008-10-02·CVSS 7.5
CVE-2007-4476 [HIGH] cpio vulnerability
Title: cpio vulnerability
Summary: cpio vulnerability
A buffer overflow was discovered in cpio. If a user were tricked into
opening a crafted cpio archive, an attacker could cause a denial of
service via application crash, or possibly execute code with the
privileges of the user invoking the program. (CVE-2007-4476)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
tar/cpio stack crashing in safer_name_suffix
vendor_redhat·2007-08-17·CVSS 7.5
CVE-2007-4476 [HIGH] tar/cpio stack crashing in safer_name_suffix
tar/cpio stack crashing in safer_name_suffix
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Statement: This issue did not affect the version of cpio as shipped with Red Hat Enterprise Linux 3 and 4.
Debian
CVE-2007-4476: cpio - Buffer overflow in the safer_name_suffix function in GNU tar has unspecified att...
vendor_debian·2007·CVSS 7.5
CVE-2007-4476 [HIGH] CVE-2007-4476: cpio - Buffer overflow in the safer_name_suffix function in GNU tar has unspecified att...
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Scope: local
bookworm: resolved (fixed in 2.9-5)
bullseye: resolved (fixed in 2.9-5)
forky: resolved (fixed in 2.9-5)
sid: resolved (fixed in 2.9-5)
trixie: resolved (fixed in 2.9-5)
No detection rules found.
Bugzilla
CVE-2007-4476 cpio stack crashing in safer_name_suffix [Fdevel]
bugzilla·2007-10-19·CVSS 7.5
CVE-2007-4476 [HIGH] CVE-2007-4476 cpio stack crashing in safer_name_suffix [Fdevel]
CVE-2007-4476 cpio stack crashing in safer_name_suffix [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Ping on this.
---
fixed in build cpio-2.9-5.fc{8|9}
Bugzilla
CVE-2007-4476 tar stack crashing in safer_name_suffix [Fdevel]
bugzilla·2007-10-19·CVSS 7.5
CVE-2007-4476 [HIGH] CVE-2007-4476 tar stack crashing in safer_name_suffix [Fdevel]
CVE-2007-4476 tar stack crashing in safer_name_suffix [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2007-4476 tar/cpio stack crashing in safer_name_suffix
bugzilla·2007-09-06·CVSS 7.5
CVE-2007-4476 [HIGH] CVE-2007-4476 tar/cpio stack crashing in safer_name_suffix
CVE-2007-4476 tar/cpio stack crashing in safer_name_suffix
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4476
to the following vulnerability:
Bug in the safer_name_suffix function in GNU tar may lead to a "crashing
stack". It can be used to crash tar while extracting archive containing file
with long name containing unsafe prefix.
Affected function is also part of cpio source code.
References:
http://www.novell.com/linux/security/advisories/2007_18_sr.html
http://lists.gnu.org/archive/html/bug-cpio/2007-08/msg00002.html
Discussion:
Upstream patch for paxutils / paxlib (used by recent versions of tar and cpio):
http://cvs.savannah.gnu.org/viewvc/paxutils/paxutils/paxlib/names.c?r1=1.2&r2=1.4
---
Created attachment 236281
patch for cpio-2.6
this patch should
http://bugs.gentoo.org/show_bug.cgi?id=196978http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://secunia.com/advisories/26674http://secunia.com/advisories/26987http://secunia.com/advisories/27331http://secunia.com/advisories/27453http://secunia.com/advisories/27514http://secunia.com/advisories/27681http://secunia.com/advisories/27857http://secunia.com/advisories/28255http://secunia.com/advisories/29968http://secunia.com/advisories/32051http://secunia.com/advisories/33567http://secunia.com/advisories/39008http://security.gentoo.org/glsa/glsa-200711-18.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1http://www.debian.org/security/2007/dsa-1438http://www.debian.org/security/2008/dsa-1566http://www.mandriva.com/security/advisories?name=MDKSA-2007:197http://www.mandriva.com/security/advisories?name=MDKSA-2007:233http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_19_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0141.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0144.htmlhttp://www.securityfocus.com/bid/26445http://www.ubuntu.com/usn/usn-650-1http://www.ubuntu.com/usn/usn-709-1http://www.vupen.com/english/advisories/2010/0628http://www.vupen.com/english/advisories/2010/0629https://bugzilla.redhat.com/show_bug.cgi?id=280961https://issues.rpath.com/browse/RPL-1861https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7114https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8599https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9336https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00073.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=196978http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://secunia.com/advisories/26674http://secunia.com/advisories/26987http://secunia.com/advisories/27331http://secunia.com/advisories/27453http://secunia.com/advisories/27514http://secunia.com/advisories/27681http://secunia.com/advisories/27857http://secunia.com/advisories/28255http://secunia.com/advisories/29968http://secunia.com/advisories/32051http://secunia.com/advisories/33567http://secunia.com/advisories/39008http://security.gentoo.org/glsa/glsa-200711-18.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1http://www.debian.org/security/2007/dsa-1438http://www.debian.org/security/2008/dsa-1566http://www.mandriva.com/security/advisories?name=MDKSA-2007:197http://www.mandriva.com/security/advisories?name=MDKSA-2007:233http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_19_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0141.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0144.htmlhttp://www.securityfocus.com/bid/26445http://www.ubuntu.com/usn/usn-650-1http://www.ubuntu.com/usn/usn-709-1http://www.vupen.com/english/advisories/2010/0628http://www.vupen.com/english/advisories/2010/0629https://bugzilla.redhat.com/show_bug.cgi?id=280961https://issues.rpath.com/browse/RPL-1861https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7114https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8599https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9336https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00073.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.html
2007-09-05
Published