Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cpioUpgrade tar | Dec 1, 2016 | Sep 4, 2007 |
| Debian | — | Upgrade cpioUpgrade tar | Jul 30, 2024 | Sep 5, 2007 |
| Freebsd | — | Upgrade gtar | Dec 10, 2025 | Jan 15, 2009 |
| Gentoo Linux | — | Upgrade app-arch/cpio. | Oct 30, 2017 | Sep 4, 2007 |
| Oracle_linux | — | Upgrade cpioUpgrade tar | Oct 16, 2024 | Sep 5, 2007 |
| Suse | — | Upgrade tarUpgrade cpioUpgrade suse-release | Feb 17, 2015 | Sep 4, 2007 |
| Ubuntu | — | Upgrade cpioUpgrade tar | Nov 8, 2024 | Sep 5, 2007 |
| Vmsa 2010 0013 | — | Upgrade VMware ESX 4.1 to build number 320092Upgrade VMware ESX 3.5 to build number 283373Upgrade VMware ESX 4.0 to build number 294855 | Nov 19, 2010 | Sep 5, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub