REDHAT-BUG-2121292: Medium severity openeuler vulnerability
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnulongname, causing an out-of-bounds read.
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1807
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2121292?
The severity of REDHAT-BUG-2121292 is considered high due to the potential for an attacker to exploit an out-of-bounds read.
How can I mitigate REDHAT-BUG-2121292?
To mitigate REDHAT-BUG-2121292, it is recommended to update the affected openEuler packages to the latest version that resolves this vulnerability.
What specific vulnerability does REDHAT-BUG-2121292 address?
REDHAT-BUG-2121292 addresses an out-of-bounds read triggered by a crafted tar file with a size header set to zero.
Which software is affected by REDHAT-BUG-2121292?
The software affected by REDHAT-BUG-2121292 includes openEuler versions that utilize the libtar library.
What is the impact of exploiting REDHAT-BUG-2121292?
Exploiting REDHAT-BUG-2121292 could allow an attacker to read sensitive information from memory, leading to potential information disclosure.