CVE-2021-20193
published 2021-03-26CVE-2021-20193: A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled…
PriorityP411low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.09%
62.0th percentile
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tar | < tar 1.34+dfsg-1 (bookworm) | tar 1.34+dfsg-1 (bookworm) |
| gnu | tar | <= 1.33 | — |
| gnu | tar | — | — |
| gnu | tar | >= 0 < 1.34+dfsg-1 | 1.34+dfsg-1 |
| gnu | tar | >= 0 < 1.34+dfsg-1 | 1.34+dfsg-1 |
| gnu | tar | >= 0 < 1.34+dfsg-1 | 1.34+dfsg-1 |
| gnu | tar | >= 0 < 1.34+dfsg-1 | 1.34+dfsg-1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
tar vulnerability
vendor_ubuntu·2022-03-15
CVE-2021-20193 tar vulnerability
Title: tar vulnerability
Summary: tar could be made to crash if it received specially crafted
file.
It was discovered that tar incorrectly handled certain files.
An attacker could possibly use this issue to cause tar to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tar: Memory leak in read_header() in list.c
vendor_redhat·2021-01-17·CVSS 3.3
CVE-2021-20193 [LOW] CWE-401 tar: Memory leak in read_header() in list.c
tar: Memory leak in read_header() in list.c
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
A flaw was found in the src/list.c of tar. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Statement: The vulnerability in GNU Tar is rated as moderate severity because, while it results in a denial of service through memory leaks, its exploitation is constrained to the application's operational context without impacting the broader system integrity or security. Th
Debian
CVE-2021-20193: tar - A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an ...
vendor_debian·2021·CVSS 3.3
CVE-2021-20193 [LOW] CVE-2021-20193: tar - A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an ...
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1.34+dfsg-1)
bullseye: resolved (fixed in 1.34+dfsg-1)
forky: resolved (fixed in 1.34+dfsg-1)
sid: resolved (fixed in 1.34+dfsg-1)
trixie: resolved (fixed in 1.34+dfsg-1)
GHSA
Out-of-bounds Read and Missing Release of Memory after Effective Lifetime in tar
ghsa_unreviewed·2021-05-27
CVE-2021-20193 [MEDIUM] CWE-125 Out-of-bounds Read and Missing Release of Memory after Effective Lifetime in tar
Out-of-bounds Read and Missing Release of Memory after Effective Lifetime in tar
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20193: A flaw was found in the src/list
osv·2021-03-26·CVSS 3.3
CVE-2021-20193 [LOW] CVE-2021-20193: A flaw was found in the src/list
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1917565https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777https://savannah.gnu.org/bugs/?59897https://security.gentoo.org/glsa/202105-29https://bugzilla.redhat.com/show_bug.cgi?id=1917565https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777https://savannah.gnu.org/bugs/?59897https://security.gentoo.org/glsa/202105-29
2021-03-26
Published