PT-2019-19939 · Gnu+6 · Gnu Tar+6
Padma81
·
Published
2019-02-24
·
Updated
2025-08-28
·
CVE-2019-9923
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Tar versions prior to 1.32
Description
The issue arises from a NULL pointer dereference in the
pax decode header function within sparse.c when parsing certain archives with malformed extended headers.Recommendations
For GNU Tar versions prior to 1.32, update to version 1.32 or later to resolve the issue.
Fix
Infinite Loop
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Gnu Tar
Linuxmint
Red Os
Suse
Ubuntu