GNU.Tar.from_header.Information.Disclosure
Description
This indicates an attack attempt to exploit an Information Disclosure Vulnerability in GNU Tar.
This vulnerability is due to a missing bounds check when reading a base-256 value in the from_header function. A remote attacker could exploit this vulnerability by enticing a victim to extract a crafted file. Successfully exploiting this vulnerability could result in denial of service or information disclosure.
Affected Products
GNU Tar 1.34 and prior
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=3da78400eafcccb97e2f2fd4b227ea40d794ede8
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2023-05-16 | 23.555 | Default_action:pass:drop |
2023-05-09 | 23.550 | Sig Added |
2023-03-15 | 23.512 |