CVE-2013-4397: Buffer Overflow
Multiple integer overflows in the thread function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4397?
CVE-2013-4397 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2013-4397?
To fix CVE-2013-4397, update libtar to version 1.2.20 or later.
What software is affected by CVE-2013-4397?
CVE-2013-4397 affects versions of libtar prior to 1.2.20 and certain versions of Red Hat Enterprise Linux 6.0.
Can CVE-2013-4397 lead to a denial of service?
Yes, CVE-2013-4397 can lead to a denial of service by crashing the application due to integer overflow vulnerabilities.
Is there any potential for remote code execution in CVE-2013-4397?
Yes, CVE-2013-4397 allows remote attackers to possibly execute arbitrary code through crafted archive files.