[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-1994 --- tar

ID: oval:org.secpod.oval:def:1701224Date: (C)2023-03-28   (M)2023-08-11
Class: PATCHFamily: unix




GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters

Platform:
Amazon Linux 2
Product:
tar
Reference:
ALAS2-2023-1994
CVE-2022-48303
CVE    1
CVE-2022-48303
CPE    2
cpe:/a:gnu:tar
cpe:/o:amazon:linux:2

© SecPod Technologies