CVE-2007-4476: Buffer Overflow

Published Aug 17, 2007
·
Updated

Buffer overflow in the safernamesuffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

Other sources

Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4476 to the following vulnerability:

Bug in the safernamesuffix function in GNU tar may lead to a "crashing stack". It can be used to crash tar while extracting archive containing file with long name containing unsafe prefix.

Affected function is also part of cpio source code.

References:

http://www.novell.com/linux/security/advisories/200718sr.html http://lists.gnu.org/archive/html/bug-cpio/2007-08/msg00002.html

Red Hat

Affected Software

9 affected componentsFixes available
redhat/tar<0:1.14-13.el4_8.1
0:1.14-13.el4_8.1
redhat/tar<2:1.15.1-23.0.1.el5_4.2
2:1.15.1-23.0.1.el5_4.2
redhat/cpio<0:2.6-23.el5_4.1
0:2.6-23.el5_4.1
GNU tar<1.19
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Canonical Ubuntu Linux=7.04
Canonical Ubuntu Linux=7.10
Canonical Ubuntu Linux=6.06

Remediation

Event History

Aug 17, 2007
CVE Published
via Red Hat·12:00 AM
Sep 5, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Sep 6, 2007
Data Sourced
via Red Hat·05:01 PM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-4476?

CVE-2007-4476 is considered a high severity vulnerability due to the potential for buffer overflow leading to crashes.

2

How do I fix CVE-2007-4476?

To fix CVE-2007-4476, update to the recommended versions of the GNU tar or cpio packages as specified by your software provider.

3

What systems are affected by CVE-2007-4476?

CVE-2007-4476 affects various versions of GNU tar, Debian Linux 3.1 and 4.0, and Ubuntu Linux 6.06, 7.04, and 7.10.

4

What type of vulnerability is CVE-2007-4476?

CVE-2007-4476 is a buffer overflow vulnerability that occurs within the safer_name_suffix function of GNU tar.

5

What are the potential impacts of CVE-2007-4476?

The potential impacts of CVE-2007-4476 include application crashes and the possibility of executing arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203