CVE-2021-33644: High severity centos libtar vulnerability
Published Aug 9, 2022
·Updated
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnulongname, causing an out-of-bounds read.
Affected Software
11 affected componentsFixes available
Feep Libtar<1.2.21
Huawei Openeuler=20.03-sp1
Huawei Openeuler=20.03-sp3
Huawei Openeuler=22.03
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
debian/libtar<=1.2.20-8
1.2.20-8+deb12u1~deb11u11.2.20-8+deb12u1
Openatom Openeuler=20.03-sp1
Openatom Openeuler=20.03-sp3
Openatom Openeuler=22.03
Event History
Aug 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Aug 25, 2022
Data Sourced
via Red Hat·05:11 AM
DescriptionSeverityAffected Software
Mar 31, 2025
Data Sourced
via Ubuntu·07:13 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-33644?
CVE-2021-33644 has a medium severity rating due to the potential for an out-of-bounds read.
2
How do I fix CVE-2021-33644?
To fix CVE-2021-33644, update to the latest version of libtar that addresses this vulnerability.
3
Which software is affected by CVE-2021-33644?
CVE-2021-33644 affects various versions of libtar and specific releases of Huawei's openEuler and Fedora.
4
Can CVE-2021-33644 be exploited remotely?
Yes, CVE-2021-33644 can potentially be exploited by an attacker submitting a crafted tar file.
5
What type of vulnerability is CVE-2021-33644?
CVE-2021-33644 is classified as a memory corruption vulnerability due to an out-of-bounds read issue.