PT-2007-7484 · Gnu+3 · Tar+3

Publicado

1970-01-01

·

Atualizado

2021-05-17

·

CVE-2007-4476

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions tar versions 1.14 through 1.15.1 Debian GNU/Linux (affected versions not specified) CentOS (affected versions not specified) Red Hat Enterprise Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the tar package of various operating systems, including Debian GNU/Linux, CentOS, and Red Hat Enterprise Linux. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. A buffer overflow in the safer name suffix function in GNU tar has been identified, resulting in a crashing stack. The vulnerabilities can be exploited remotely.
Recommendations For tar versions 1.14 through 1.15.1, consider disabling the safer name suffix function as a temporary workaround until a patch is available. For Debian GNU/Linux, update to a version that includes the fix for the tar package vulnerabilities. For CentOS, update to a version that includes the fix for the tar package vulnerabilities. For Red Hat Enterprise Linux, update to a version that includes the fix for the tar package vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability in some of the affected operating systems.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01807
BDU:2015-01999
BDU:2015-06547
BDU:2015-06548
BDU:2015-08363
BDU:2015-08364
CVE-2007-4476
DSA-1438-1
DSA-1566-1
RHSA-2010:0141
RHSA-2010:0144
RHSA-2010_0141
RHSA-2010_0144

Produtos afetados

Centos
Debian
Red Hat
Tar