Known Vulnerabilities for Tar by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Tar" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-20193 | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file ... | 5.5 - MEDIUM | 2021-03-26 | 2023-11-07 |
| CVE-2019-9923 | pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have m... | 7.5 - HIGH | 2019-03-22 | 2023-11-07 |
| CVE-2018-20482 | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause ... | 4.7 - MEDIUM | 2018-12-26 | 2021-11-30 |
| CVE-2016-6321 | Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers... | 7.5 - HIGH | 2016-12-09 | 2023-02-13 |
| CVE-2010-0624 | Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.2... | 6.8 - MEDIUM | 2010-03-15 | 2018-10-10 |
| CVE-2007-4476 | Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crash... | 7.5 - HIGH | 2007-09-05 | 2021-05-17 |
| CVE-2007-4131 | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote atta... | 6.8 - MEDIUM | 2007-08-25 | 2018-10-15 |
| CVE-2006-6097 | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar f... | 4 - MEDIUM | 2006-11-24 | 2018-10-17 |
| CVE-2006-0300 | Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) a... | 5.1 - MEDIUM | 2006-02-24 | 2018-10-19 |
| CVE-2005-1918 | The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses... | 2.6 - LOW | 2005-12-31 | 2018-10-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Tar | 1.32 | All | All | All |
| Application | Gnu | Tar | 1.31 | All | All | All |
| Application | Gnu | Tar | 1.30 | All | All | All |
| Application | Gnu | Tar | 1.29 | All | All | All |
| Application | Gnu | Tar | 1.28 | All | All | All |
| Application | Gnu | Tar | 1.27.1 | All | All | All |
| Application | Gnu | Tar | 1.27 | All | All | All |
| Application | Gnu | Tar | 1.26 | All | All | All |
| Application | Gnu | Tar | 1.25 | All | All | All |
| Application | Gnu | Tar | 1.24 | All | All | All |
| Application | Gnu | Tar | 1.23 | All | All | All |
| Application | Gnu | Tar | 1.22 | All | All | All |
| Application | Gnu | Tar | 1.21 | All | All | All |
| Application | Gnu | Tar | 1.20 | All | All | All |
| Application | Gnu | Tar | 1.19 | All | All | All |
| Application | Gnu | Tar | 1.18 | All | All | All |
| Application | Gnu | Tar | 1.17 | All | All | All |
| Application | Gnu | Tar | 1.16.1 | All | All | All |
| Application | Gnu | Tar | 1.16 | All | All | All |
| Application | Gnu | Tar | 1.15.91 | All | All | All |