REDHAT-BUG-2121289: Medium severity openeuler vulnerability
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnulonglink, causing an out-of-bounds read.
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1807
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2121289?
The severity of REDHAT-BUG-2121289 is classified as high due to the potential for an out-of-bounds read.
How do I fix REDHAT-BUG-2121289?
To fix REDHAT-BUG-2121289, it is recommended to update the vulnerable package to the latest version provided by your distribution.
What systems are affected by REDHAT-BUG-2121289?
REDHAT-BUG-2121289 affects systems running openEuler, specifically versions vulnerable to the crafted tar file exploit.
What kind of attack does REDHAT-BUG-2121289 facilitate?
REDHAT-BUG-2121289 facilitates an out-of-bounds read attack by allowing an attacker to submit a specially crafted tar file.
What components does REDHAT-BUG-2121289 impact?
REDHAT-BUG-2121289 impacts the libtar library, which processes tar files within the affected systems.