CVE-2018-20482
Summary
| CVE | CVE-2018-20482 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-26 18:29:00 UTC |
| Updated | 2021-11-30 19:52:00 UTC |
| Description | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2830-1] tar security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 1623-1] tar security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| GNU Tar CVE-2018-20482 Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [security-announce] openSUSE-SU-2019:1237-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| How I wound up finding a bug in GNU Tar | Hacker News |
MISC |
news.ycombinator.com |
Exploit, Third Party Advisory |
| Chris's Wiki :: blog/sysadmin/TarFindingTruncateBug |
MISC |
utcc.utoronto.ca |
Patch, Third Party Advisory |
| Chris Siebenmann na Twitterze: "Current status: I just confirmed a bug in GNU Tar that causes our backups to hang every so often if we're unlucky. As usual I'm half-dreading the experience of trying to report the bug." |
MISC |
twitter.com |
Patch, Third Party Advisory |
| tar.git - GNU Tar |
MISC |
git.savannah.gnu.org |
Patch, Third Party Advisory |
| [Bug-tar] GNU Tar with --sparse can loop endlessly if a file shrinks whi |
MISC |
lists.gnu.org |
Third Party Advisory |
| Tar: Denial of Service (GLSA 201903-05) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178916 Debian Security Update for tar (DLA 2830-1)
- 296092 Oracle Solaris 11.4 Support Repository Update (SRU) 7.1.4 Missing (CPUJAN2019)
- 500682 Alpine Linux Security Update for tar
- 504451 Alpine Linux Security Update for tar
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 710193 Gentoo Linux Tar Denial of service Vulnerability (GLSA 201903-05)
- 752108 SUSE Enterprise Linux Security Update for tar (SUSE-SU-2022:1548-1)