GNU Tar through 1.34 has a one-byte out-of-bounds read...
High severity
Unreviewed
Published
Jan 30, 2023
to the GitHub Advisory Database
•
Updated Mar 27, 2023
Description
Published by the National Vulnerability Database
Jan 30, 2023
Published to the GitHub Advisory Database
Jan 30, 2023
Last updated
Mar 27, 2023
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
References