In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tarUpgrade tar-debuginfo | Jan 10, 2024 | Jan 10, 2024 |
| Amazon_linux_2023 | — | Upgrade tarUpgrade tar-debugsourceUpgrade tar-debuginfo | Feb 17, 2025 | Dec 11, 2023 |
| Debian | — | Upgrade tar | Mar 11, 2024 | Mar 11, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade tar | Mar 13, 2024 | Mar 13, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade tar | Mar 13, 2024 | Mar 13, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade tar | Feb 12, 2024 | Feb 8, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2024 |
| Suse | — | Upgrade tar-docUpgrade tarUpgrade tar-langUpgrade tar-backup-scriptsUpgrade tar-testsUpgrade tar-rmt | Jan 10, 2024 | Jan 9, 2024 |
| Ubuntu | — | Upgrade tarUpgrade tar (Ubuntu Pro) | Dec 12, 2023 | Dec 11, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub