CVE-2021-33643: Critical severity Feep Libtar vulnerability
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnulonglink, causing an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libtarto a version that resolves this vulnerability.Fixed in 1.2.20-8+deb12u1~deb11u1Fixed in 1.2.20-8+deb12u1 - Upgrade
Upgrade
debian/libtarto a version that resolves this vulnerability.Fixed in 1.2.20-8+deb12u1~deb11u1 - Upgrade
Upgrade
debian/libtarto a version that resolves this vulnerability.Fixed in 1.2.20-8+deb12u1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33643?
The severity of CVE-2021-33643 is classified as a medium vulnerability due to the potential for an out-of-bounds read.
How do I fix CVE-2021-33643?
To fix CVE-2021-33643, upgrade to a patched version of libtar that addresses this vulnerability.
Which versions of libtar are affected by CVE-2021-33643?
CVE-2021-33643 affects libtar versions prior to 1.2.21.
What types of systems are vulnerable to CVE-2021-33643?
CVE-2021-33643 impacts systems running vulnerable versions of Huawei openEuler and Fedora.
What could happen if CVE-2021-33643 is exploited?
If exploited, CVE-2021-33643 could lead to unintended memory access, potentially resulting in information leakage.