REDHAT-BUG-1917565: Medium severity ubuntu tar vulnerability
Published Jan 18, 2021
·Updated
An issue was discovered in GNU Tar 1.33 and earlier. There is a memory leak in readheader() in list.c in the tar application.
Upstream bug:
https://savannah.gnu.org/bugs/?59897
Upstream patch:
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777
Affected Software
1 affected component
GNU tar<1.33
Event History
Jan 18, 2021
Data Sourced
via Red Hat·06:35 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1917565?
The severity of REDHAT-BUG-1917565 is classified as a memory leak in GNU Tar versions 1.33 and earlier.
2
How do I fix REDHAT-BUG-1917565?
To fix REDHAT-BUG-1917565, update GNU Tar to a version later than 1.33 that includes the patch for this issue.
3
What versions of GNU Tar are affected by REDHAT-BUG-1917565?
GNU Tar versions 1.33 and earlier are affected by REDHAT-BUG-1917565.
4
What component of GNU Tar is involved in REDHAT-BUG-1917565?
The component involved in REDHAT-BUG-1917565 is the read_header() function in list.c.
5
Is there an upstream patch for REDHAT-BUG-1917565?
Yes, there is an upstream patch available to address REDHAT-BUG-1917565.