CVE-2023-39804
published 2024-03-27CVE-2023-39804: In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
PriorityP419medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.28%
20.2th percentile
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tar | < tar 1.34+dfsg-1.2+deb12u1 (bookworm) | tar 1.34+dfsg-1.2+deb12u1 (bookworm) |
| gnu | tar | < 1.35 | 1.35 |
| gnu | tar | >= 0 < 1.34+dfsg-1+deb11u1 | 1.34+dfsg-1+deb11u1 |
| gnu | tar | >= 0 < 1.34+dfsg-1.2+deb12u1 | 1.34+dfsg-1.2+deb12u1 |
| gnu | tar | >= 0 < 1.34+dfsg-1.3 | 1.34+dfsg-1.3 |
| gnu | tar | >= 0 < 1.34+dfsg-1.3 | 1.34+dfsg-1.3 |
| msrc | cbl2_tar_1.34-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_msrc6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-39804: In GNU tar before 1
osv·2024-03-27·CVSS 6.2
CVE-2023-39804 [MEDIUM] CVE-2023-39804: In GNU tar before 1
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
GHSA
GHSA-5pvw-wf9w-xx8v: In GNU tar before 1
ghsa_unreviewed·2024-03-27
CVE-2023-39804 [MEDIUM] GHSA-5pvw-wf9w-xx8v: In GNU tar before 1
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Microsoft
In GNU tar before 1.35 mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
vendor_msrc·2024-03-12·CVSS 6.2
CVE-2023-39804 [MEDIUM] In GNU tar before 1.35 mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
In GNU tar before 1.35 mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
MITRE: MITRE
Customer Action Required: Y
Ubuntu
GNU Tar vulnerability
vendor_ubuntu·2023-12-11
CVE-2023-39804 GNU Tar vulnerability
Title: GNU Tar vulnerability
Summary: tar could be made to crash if it opened a specially crafted file.
It was discovered that tar incorrectly handled extended attributes in PAX
archives. An attacker could use this issue to cause tar to crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tar: Incorrectly handled extension attributes in PAX archives can lead to a crash
vendor_redhat·2023-12-11·CVSS 6.2
CVE-2023-39804 [MEDIUM] CWE-121 tar: Incorrectly handled extension attributes in PAX archives can lead to a crash
tar: Incorrectly handled extension attributes in PAX archives can lead to a crash
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service.
Statement: To exploit this flaw, an attacker needs to trick a user into processing a malicious archive, causing only an application crash. For these reasons, this flaw was rated with a low, and not moderate, severity.
Mitigation: Do not process untrusted tar archives.
Package: tar (Red Hat Enterprise Linux 6) - Out of support scope
Package: tar (Red Hat Enterprise Linux 7) - Fix deferred
Package:
Debian
CVE-2023-39804: tar - In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lea...
vendor_debian·2023·CVSS 6.2
CVE-2023-39804 [MEDIUM] CVE-2023-39804: tar - In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lea...
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Scope: local
bookworm: resolved (fixed in 1.34+dfsg-1.2+deb12u1)
bullseye: resolved (fixed in 1.34+dfsg-1+deb11u1)
forky: resolved (fixed in 1.34+dfsg-1.3)
sid: resolved (fixed in 1.34+dfsg-1.3)
trixie: resolved (fixed in 1.34+dfsg-1.3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html
2024-03-27
Published