USN-6543-1: GNU Tar vulnerability
It was discovered that tar incorrectly handled extended attributes in PAX archives. An attacker could use this issue to cause tar to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6543-1?
The severity of USN-6543-1 is not specified.
What is the affected software for USN-6543-1?
The affected software for USN-6543-1 is the tar package on various versions of Ubuntu.
How does the vulnerability in USN-6543-1 impact the system?
The vulnerability in USN-6543-1 could allow an attacker to crash the tar program, resulting in a denial of service.
How can I fix the vulnerability in USN-6543-1?
To fix the vulnerability in USN-6543-1, update the tar package to the recommended version provided by Ubuntu.
Where can I find more information about USN-6543-1?
More information about USN-6543-1 can be found at the following references: [CVE-2023-39804](https://ubuntu.com/security/CVE-2023-39804), [Ubuntu Security Notice](https://launchpad.net/ubuntu/+source/tar/1.34+dfsg-1.2ubuntu1.1), [Ubuntu Launchpad](https://launchpad.net/ubuntu/+source/tar/1.34+dfsg-1.2ubuntu0.2)