CVE-2022-48303
published 2023-01-30CVE-2022-48303: GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of…
PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
4.52%
90.5th percentile
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tar | < tar 1.34+dfsg-1.2+deb12u1 (bookworm) | tar 1.34+dfsg-1.2+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | tar | <= 1.34 | — |
| gnu | tar | >= 0 < 1.34+dfsg-1+deb11u1 | 1.34+dfsg-1+deb11u1 |
| gnu | tar | >= 0 < 1.34+dfsg-1.2+deb12u1 | 1.34+dfsg-1.2+deb12u1 |
| gnu | tar | >= 0 < 1.34+dfsg-1.4 | 1.34+dfsg-1.4 |
| gnu | tar | >= 0 < 1.34+dfsg-1.4 | 1.34+dfsg-1.4 |
| msrc | cbl2_tar_1.34-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48303: GNU Tar through 1
osv·2023-01-30·CVSS 5.5
CVE-2022-48303 [MEDIUM] CVE-2022-48303: GNU Tar through 1
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
GHSA
GHSA-h2v4-4v4p-2qvc: GNU Tar through 1
ghsa_unreviewed·2023-01-30
CVE-2022-48303 [HIGH] CWE-125 GHSA-h2v4-4v4p-2qvc: GNU Tar through 1
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
tar vulnerability
vendor_ubuntu·2023-05-22
CVE-2022-48303 tar vulnerability
Title: tar vulnerability
Summary: tar could be made to crash or expose sensitive information
if it received a specially crafted file.
USN-5900-1 fixed vulnerabilities in tar. This update fixes it to Ubuntu 23.04.
Original advisory details:
It was discovered that tar incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information
or cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
tar vulnerability
vendor_ubuntu·2023-02-28
CVE-2022-48303 tar vulnerability
Title: tar vulnerability
Summary: tar could be made to crash or expose sensitive information
if it received a specially crafted file.
It was discovered that tar incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information
or cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump
vendor_msrc·2023-01-10·CVSS 5.5
CVE-2022-48303 [MEDIUM] CWE-125 GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
MITRE: MITRE
Customer Action Required
Red Hat
tar: heap buffer overflow at from_header() in list.c via specially crafted checksum
vendor_redhat·2022-04-30·CVSS 5.5
CVE-2022-48303 [MEDIUM] CWE-119 tar: heap buffer overflow at from_header() in list.c via specially crafted checksum
tar: heap buffer overflow at from_header() in list.c via specially crafted checksum
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
A flaw was found in the Tar package. When attempting to read files with old V7 tar format with a specially crafted checksum, an invalid memory read may occur. An attacker could possibly use this issue to expose sensitive information or cause a crash.
Package: tar (Red Hat Enterprise Linux 6) - Out of support scope
Package: tar (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2022-48303: tar - GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of un...
vendor_debian·2022·CVSS 5.5
CVE-2022-48303 [MEDIUM] CVE-2022-48303: tar - GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of un...
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
Scope: local
bookworm: resolved (fixed in 1.34+dfsg-1.2+deb12u1)
bullseye: resolved (fixed in 1.34+dfsg-1+deb11u1)
forky: resolved (fixed in 1.34+dfsg-1.4)
sid: resolved (fixed in 1.34+dfsg-1.4)
trixie: resolved (fixed in 1.34+dfsg-1.4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZNSVYDYYUD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7KXHLRZQS4/https://savannah.gnu.org/bugs/?62387https://savannah.gnu.org/patch/?10307https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZNSVYDYYUD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7KXHLRZQS4/https://savannah.gnu.org/bugs/?62387https://savannah.gnu.org/patch/?10307
2023-01-30
Published