Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-4397


Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.


Published

2013-10-17T23:55:04.580

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System redhat enterprise_linux 6.0 Yes
Application feep libtar ≤ 1.2.19 Yes
Application feep libtar 1.2.11 Yes
Application feep libtar 1.2.13 Yes
Application feep libtar 1.2.14 Yes
Application feep libtar 1.2.15 Yes
Application feep libtar 1.2.16 Yes
Application feep libtar 1.2.17 Yes
Application feep libtar 1.2.18 Yes

References