Description
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages2 packages
▶Debiangnu/tar< 1.34+dfsg-1+deb11u1+3 🔴Vulnerability Details
3OSVCVE-2023-39804: In GNU tar before 1↗2024-03-27 ▶ GHSAGHSA-5pvw-wf9w-xx8v: In GNU tar before 1↗2024-03-27 ▶ CVEListCVE-2023-39804: In GNU tar before 1↗2024-03-27 ▶ 📋Vendor Advisories
4MicrosoftIn GNU tar before 1.35 mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.↗2024-03-12 ▶ UbuntuGNU Tar vulnerability↗2023-12-11 ▶ Red Hattar: Incorrectly handled extension attributes in PAX archives can lead to a crash↗2023-12-11 ▶ DebianCVE-2023-39804: tar - In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lea...↗2023 ▶