OSVDB ID: 23371

Title: GNU tar PAX Extended Headers Handling Overflow

Info

Disclosure

Feb 22, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in GNU Tar. GNU Tar fails to properly handle PAX extended headers resulting in a buffer overflow. With a specially crafted .tar archive, an attacker can cause arbitrary command execution when the victim lists the tar contents or extracts the archive.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.15.90 (alpha) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

GNU

Tar

1.15.1

References

Credit

  • Jim Meyering - jimmeyering.net -


Direct URL: http://osvdb.org/23371