First published: Mon Jan 18 2021(Updated: )
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU tar | <=1.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20193 is a vulnerability found in the src/list.c file of tar versions 1.33 and earlier.
The highest threat from CVE-2021-20193 is to system availability.
CVE-2021-20193 affects GNU tar versions 1.33 and earlier.
An attacker can exploit CVE-2021-20193 by submitting a crafted input file to tar, causing uncontrolled consumption of memory.
CVE-2021-20193 has a severity rating of medium (5.5).