CVE-2021-20193
Summary
| CVE | CVE-2021-20193 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-26 17:15:00 UTC |
| Updated | 2023-11-07 03:28:00 UTC |
| Description | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability. |
Risk And Classification
Problem Types: CWE-125 | CWE-401
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GNU tar - Bugs: bug #59897, Memory Leak GNU Tar 1.33 [Savannah] | MISC | savannah.gnu.org | |
| 1917565 – (CVE-2021-20193) CVE-2021-20193 tar: Memory leak in read_header() in list.c | MISC | bugzilla.redhat.com | |
| Tar: Denial of service (GLSA 202105-29) — Gentoo security | GENTOO | security.gentoo.org | |
| tar.git - GNU Tar | MISC | git.savannah.gnu.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174868 SUSE Enterprise Linux Security Update for tar (SUSE-SU-2021:0974-1)
- 174869 SUSE Enterprise Linux Security update for tar (SUSE-SU-2021:0975-1)
- 179918 Debian Security Update for tar (CVE-2021-20193)
- 198703 Ubuntu Security Notification for tar Vulnerability (USN-5329-1)
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 500683 Alpine Linux Security Update for tar
- 501503 Alpine Linux Security Update for tar
- 504452 Alpine Linux Security Update for tar
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670221 EulerOS Security Update for tar (EulerOS-SA-2021-1854)
- 670474 EulerOS Security Update for tar (EulerOS-SA-2021-2232)
- 670676 EulerOS Security Update for tar (EulerOS-SA-2021-2434)
- 670730 EulerOS Security Update for tar (EulerOS-SA-2021-2488)
- 670785 EulerOS Security Update for tar (EulerOS-SA-2021-2543)
- 670809 EulerOS Security Update for tar (EulerOS-SA-2021-2567)
- 670850 EulerOS Security Update for tar (EulerOS-SA-2021-1854)
- 710085 Gentoo Linux Tar Denial of service (GLSA 202105-29)
- 750286 OpenSUSE Security Update for tar (openSUSE-SU-2021:0494-1)
- 752108 SUSE Enterprise Linux Security Update for tar (SUSE-SU-2022:1548-1)