Out-of-bounds Read and Missing Release of Memory after Effective Lifetime in tar
Moderate severity
Unreviewed
Published
May 27, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 26, 2021
Published to the GitHub Advisory Database
May 27, 2021
Last updated
Feb 1, 2023
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
References