First published: Fri Feb 12 2010(Updated: )
A heap-based buffer overflow flaw was found in the way tar and cpio archive manipulation tools expanded archives with certain character in the archive name. If a local user was tricked into expanding a specially-crafted archive, it could cause the tar, cpio executables to crash or, potentially, to execute arbitrary code with the privileges of the user running the utility. Link to advisory: [1] <a href="http://www.agrs.tu-berlin.de/index.php?id=78327">http://www.agrs.tu-berlin.de/index.php?id=78327</a> Acknowledgements: Red Hat would like to thank Jakob Lell for responsibly reporting this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu tar | =1.14.1 | |
Ubuntu tar | =1.13.17 | |
GNU Cpio | =2.9 | |
Ubuntu tar | =1.13.25 | |
Ubuntu tar | <=1.22 | |
GNU Cpio | =2.5.90 | |
Ubuntu tar | =1.13 | |
GNU Cpio | =1.1 | |
Ubuntu tar | =1.13.5 | |
GNU Cpio | =1.3 | |
Ubuntu tar | =1.18 | |
Ubuntu tar | =1.13.18 | |
Ubuntu tar | =1.19 | |
Ubuntu tar | =1.20 | |
GNU Cpio | =2.7 | |
Ubuntu tar | =1.17 | |
GNU Cpio | =1.2 | |
Ubuntu tar | =1.15.90 | |
Ubuntu tar | =1.16 | |
GNU Cpio | =2.6 | |
GNU Cpio | <=2.10 | |
Ubuntu tar | =1.14 | |
Ubuntu tar | =1.13.14 | |
Ubuntu tar | =1.15.91 | |
Ubuntu tar | =1.13.19 | |
Ubuntu tar | =1.14.90 | |
GNU Cpio | =2.5 | |
Ubuntu tar | =1.15 | |
GNU Cpio | =1.0 | |
Ubuntu tar | =1.13.11 | |
Ubuntu tar | =1.15.1 | |
GNU Cpio | =2.8 | |
Ubuntu tar | =1.13.16 | |
GNU Cpio | =2.4-2 | |
Ubuntu tar | =1.21 | |
Ubuntu tar | =1.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0624 has a medium severity rating due to the potential for a heap-based buffer overflow that can lead to crashes or arbitrary code execution.
To fix CVE-2010-0624, you should upgrade to a patched version of GNU tar or GNU cpio, which resolves the buffer overflow vulnerability.
CVE-2010-0624 affects various versions of GNU tar prior to 1.22 and certain versions of GNU cpio, specifically earlier than 2.10.
CVE-2010-0624 is primarily an issue for local users, as it requires users to be tricked into expanding malicious archives.
Exploitation of CVE-2010-0624 can potentially lead to denial-of-service attacks, crashes of applications, or arbitrary code execution based on the crafted archive.