CVE-2021-20193: Medium severity ubuntu tar vulnerability
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
Other sources
An issue was discovered in GNU Tar 1.33 and earlier. There is a memory leak in readheader() in list.c in the tar application.
Upstream bug:
https://savannah.gnu.org/bugs/?59897
Upstream patch:
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20193?
CVE-2021-20193 is a vulnerability found in the src/list.c file of tar versions 1.33 and earlier.
What is the impact of CVE-2021-20193?
The highest threat from CVE-2021-20193 is to system availability.
How does CVE-2021-20193 affect GNU tar?
CVE-2021-20193 affects GNU tar versions 1.33 and earlier.
How can an attacker exploit CVE-2021-20193?
An attacker can exploit CVE-2021-20193 by submitting a crafted input file to tar, causing uncontrolled consumption of memory.
What is the severity of CVE-2021-20193?
CVE-2021-20193 has a severity rating of medium (5.5).