CVE-2023-39804: Medium severity GNU tar vulnerability
In GNU tar before 1.35 mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Other sources
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.29 - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.30+dfsg-7ubuntu0.20.04.4 - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.34+dfsg-1ubuntu0.1.22.04.2 - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.34+dfsg-1.2ubuntu0.2 - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.34+dfsg-1.2ubuntu1.1 - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.27.1-1ubuntu0.1+ - Upgrade
Upgrade
ubuntu/tarto a version that resolves this vulnerability.Fixed in 1.28-2.1ubuntu0.2+ - Upgrade
Upgrade
debian/tarto a version that resolves this vulnerability.Fixed in 1.34+dfsg-1+deb11u1Fixed in 1.34+dfsg-1.2+deb12u1Fixed in 1.35+dfsg-3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.34-3
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39804?
CVE-2023-39804 is considered to have a medium severity due to potential application crashes.
How do I fix CVE-2023-39804?
To fix CVE-2023-39804, upgrade GNU tar to version 1.35 or later.
Which versions of tar are affected by CVE-2023-39804?
GNU tar versions prior to 1.35 are affected by CVE-2023-39804.
What operating systems are impacted by CVE-2023-39804?
CVE-2023-39804 impacts multiple Linux distributions including Ubuntu and Debian.
Can CVE-2023-39804 cause data loss?
CVE-2023-39804 does not directly lead to data loss, but it can cause application crashes that may disrupt normal operations.