UBUNTU-CVE-2018-20482
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-20482
UBUNTU-CVE-2018-20482
Summary:
Details: GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
References: https://ubuntu.com/security/CVE-2018-20482, https://utcc.utoronto.ca/~cks/space/blog/sysadmin/TarFindingTruncateBug, https://news.ycombinator.com/item?id=18745431, https://twitter.com/thatcks/status/1076166645708668928, http://lists.gnu.org/archive/html/bug-tar/2018-12/msg00023.html, https://ubuntu.com/security/notices/USN-4692-1, https://www.cve.org/CVERecord?id=CVE-2018-20482
Affected packages
Package
Name: tar
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
