cbcvebase.
CVE-2010-0624
published 2010-03-15

CVE-2010-0624: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows…

PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.75%
90.9th percentile
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debiancpio< cpio 2.11-1 (bookworm)cpio 2.11-1 (bookworm)
debiantar< cpio 2.11-1 (bookworm)cpio 2.11-1 (bookworm)
gnucpio<= 2.10
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio
gnucpio>= 0 < 2.11-12.11-1
gnucpio>= 0 < 2.11-12.11-1
gnucpio>= 0 < 2.11-12.11-1
gnucpio>= 0 < 2.11-12.11-1
gnucpio>= 0 < 2.11+dfsg-1ubuntu1.12.11+dfsg-1ubuntu1.1
gnutar<= 1.22
gnutar
gnutar
gnutar
gnutar
gnutar

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.