In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tar-debuginfoUpgrade tar | Jan 10, 2024 | Jan 10, 2024 |
| Amazon_linux_2023 | — | Upgrade tar-debuginfoUpgrade tarUpgrade tar-debugsource | Feb 17, 2025 | Dec 11, 2023 |
| Debian | — | Upgrade tar | Mar 11, 2024 | Mar 11, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade tar | Mar 13, 2024 | Mar 13, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade tar | Mar 13, 2024 | Mar 13, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade tar | Feb 12, 2024 | Feb 8, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2024 |
| Suse | — | Upgrade tar-langUpgrade tar-docUpgrade tar-testsUpgrade tarUpgrade tar-backup-scriptsUpgrade tar-rmt | Jan 10, 2024 | Jan 9, 2024 |
| Ubuntu | — | Upgrade tar (Ubuntu Pro)Upgrade tar | Dec 12, 2023 | Dec 11, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub