OESA-2022-1807
Dashboard / Vulnerabilities / OESA-2022-1807
OESA-2022-1807
Summary: libtar security update
Details: Libtar is a C library for manipulating POSIX tar files. It handles adding and extracting files to/from a tar archive. Requires gcc, make, and zlib. Security Fix(es): An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.(CVE-2021-33643) An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.(CVE-2021-33644) The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.(CVE-2021-33645) The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.(CVE-2021-33646)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1807, https://nvd.nist.gov/vuln/detail/CVE-2021-33643, https://nvd.nist.gov/vuln/detail/CVE-2021-33644, https://nvd.nist.gov/vuln/detail/CVE-2021-33645, https://nvd.nist.gov/vuln/detail/CVE-2021-33646
Affected packages
Package
Name: libtar
Purl: pkg:rpm/openEuler/libtar&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
