CVE-2010-0624
published 2010-03-15CVE-2010-0624: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.75%
90.9th percentile
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.11-1 (bookworm) | cpio 2.11-1 (bookworm) |
| debian | tar | < cpio 2.11-1 (bookworm) | cpio 2.11-1 (bookworm) |
| gnu | cpio | <= 2.10 | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | — | — |
| gnu | cpio | >= 0 < 2.11-1 | 2.11-1 |
| gnu | cpio | >= 0 < 2.11-1 | 2.11-1 |
| gnu | cpio | >= 0 < 2.11-1 | 2.11-1 |
| gnu | cpio | >= 0 < 2.11-1 | 2.11-1 |
| gnu | cpio | >= 0 < 2.11+dfsg-1ubuntu1.1 | 2.11+dfsg-1ubuntu1.1 |
| gnu | tar | <= 1.22 | — |
| gnu | tar | — | — |
| gnu | tar | — | — |
| gnu | tar | — | — |
| gnu | tar | — | — |
| gnu | tar | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2015-01-08·CVSS 6.8
CVE-2010-0624 [MEDIUM] GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: The GNU cpio program could be made to crash or run programs if it
opened a specially crafted file or received specially crafted input.
Michal Zalewski discovered an out of bounds write issue in the
process_copy_in function of GNU cpio. An attacker could specially
craft a cpio archive that could create a denial of service or possibly
execute arbitrary code. (CVE-2014-9112)
Jakob Lell discovered a heap-based buffer overflow in the rmt_read__
function of GNU cpio's rmt client functionality. An attacker
controlling a remote rmt server could use this to cause a denial of
service or possibly execute arbitrary code. This issue only affected
Ubuntu 10.04 LTS. (CVE-2010-0624)
Instructions: In general, a standard system update will make all the necessary
Red Hat
cpio: Heap-based buffer overflow by expanding a specially-crafted archive
vendor_redhat·2010-03-10·CVSS 6.8
CVE-2010-0624 [MEDIUM] CWE-122 cpio: Heap-based buffer overflow by expanding a specially-crafted archive
cpio: Heap-based buffer overflow by expanding a specially-crafted archive
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
Debian
CVE-2010-0624: cpio - Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the r...
vendor_debian·2010·CVSS 6.8
CVE-2010-0624 [MEDIUM] CVE-2010-0624: cpio - Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the r...
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
Scope: local
bookworm: resolved (fixed in 2.11-1)
bullseye: resolved (fixed in 2.11-1)
forky: resolved (fixed in 2.11-1)
sid: resolved (fixed in 2.11-1)
trixie: resolved (fixed in 2.11-1)
GHSA
GHSA-27jj-5xgw-m6qw: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib
ghsa_unreviewed·2022-05-02
CVE-2010-0624 [MEDIUM] CWE-119 GHSA-27jj-5xgw-m6qw: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
OSV
cpio vulnerabilities
osv·2015-01-08·CVSS 6.8
CVE-2014-9112 [MEDIUM] cpio vulnerabilities
cpio vulnerabilities
Michal Zalewski discovered an out of bounds write issue in the
process_copy_in function of GNU cpio. An attacker could specially
craft a cpio archive that could create a denial of service or possibly
execute arbitrary code. (CVE-2014-9112)
Jakob Lell discovered a heap-based buffer overflow in the rmt_read__
function of GNU cpio's rmt client functionality. An attacker
controlling a remote rmt server could use this to cause a denial of
service or possibly execute arbitrary code. This issue only affected
Ubuntu 10.04 LTS. (CVE-2010-0624)
OSV
CVE-2010-0624: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib
osv·2010-03-15·CVSS 6.8
CVE-2010-0624 [MEDIUM] CVE-2010-0624: Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
bugzilla·2010-03-10·CVSS 6.8
CVE-2010-0624 [MEDIUM] CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #564368:
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=securit
Bugzilla
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
bugzilla·2010-03-10·CVSS 6.8
CVE-2010-0624 [MEDIUM] CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #564368:
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=securit
Bugzilla
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive
bugzilla·2010-02-12·CVSS 6.8
CVE-2010-0624 [MEDIUM] CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive
CVE-2010-0624 tar, cpio: Heap-based buffer overflow by expanding a specially-crafted archive
A heap-based buffer overflow flaw was found in the way tar and
cpio archive manipulation tools expanded archives with certain
character in the archive name. If a local user was tricked into
expanding a specially-crafted archive, it could cause the tar,
cpio executables to crash or, potentially, to execute arbitrary
code with the privileges of the user running the utility.
Link to advisory:
[1] http://www.agrs.tu-berlin.de/index.php?id=78327
Acknowledgements:
Red Hat would like to thank Jakob Lell for responsibly reporting
this issue.
Discussion:
Created attachment 395483
Patch to fix rtapelib overflow
This simple twoliner patch should fix the issue.
---
Public now via [1], removing embargo
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://osvdb.org/62950http://secunia.com/advisories/38869http://secunia.com/advisories/38988http://secunia.com/advisories/39008http://security.gentoo.org/glsa/glsa-201111-11.xmlhttp://www.agrs.tu-berlin.de/index.php?id=78327http://www.mandriva.com/security/advisories?name=MDVSA-2010:065http://www.redhat.com/support/errata/RHSA-2010-0141.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0142.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0144.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0145.htmlhttp://www.securityfocus.com/archive/1/514503/100/0/threadedhttp://www.ubuntu.com/usn/USN-2456-1http://www.vupen.com/english/advisories/2010/0628http://www.vupen.com/english/advisories/2010/0629http://www.vupen.com/english/advisories/2010/0639http://www.vupen.com/english/advisories/2010/0687http://www.vupen.com/english/advisories/2010/0728http://www.vupen.com/english/advisories/2010/0729http://www.vupen.com/english/advisories/2010/1107https://bugzilla.redhat.com/show_bug.cgi?id=564368https://issues.rpath.com/browse/RPL-3219https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6907http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://osvdb.org/62950http://secunia.com/advisories/38869http://secunia.com/advisories/38988http://secunia.com/advisories/39008http://security.gentoo.org/glsa/glsa-201111-11.xmlhttp://www.agrs.tu-berlin.de/index.php?id=78327http://www.mandriva.com/security/advisories?name=MDVSA-2010:065http://www.redhat.com/support/errata/RHSA-2010-0141.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0142.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0144.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0145.htmlhttp://www.securityfocus.com/archive/1/514503/100/0/threadedhttp://www.ubuntu.com/usn/USN-2456-1http://www.vupen.com/english/advisories/2010/0628http://www.vupen.com/english/advisories/2010/0629http://www.vupen.com/english/advisories/2010/0639http://www.vupen.com/english/advisories/2010/0687http://www.vupen.com/english/advisories/2010/0728http://www.vupen.com/english/advisories/2010/0729http://www.vupen.com/english/advisories/2010/1107https://bugzilla.redhat.com/show_bug.cgi?id=564368https://issues.rpath.com/browse/RPL-3219https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6907
2010-03-15
Published