Gnu Tar vulnerabilities
43 known vulnerabilities affecting gnu/tar.
Total CVEs
43
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM18LOW3
Vulnerabilities
Page 3 of 3
CVE-2018-20482P4MEDIUMCVSS 4.7≤ 1.302018-12-26
CVE-2018-20482 [MEDIUM] CWE-835 CVE-2018-20482: GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which all
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
nvdosv
CVE-2001-1267P4LOWCVSS 2.1≤ 1.13.192001-07-12
CVE-2001-1267 [LOW] CVE-2001-1267: Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arb
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
nvd
CVE-2021-20193P4LOWCVSS 3.3≤ 1.33v1.33 and earlier2021-03-26
CVE-2021-20193 [LOW] CWE-401 CVE-2021-20193: A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can sub
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
nvdosv
← Previous3 / 3