vendor:
tar and cpio utilities
by:
Not mentioned
7.5
CVSS
HIGH
Denial-of-Service
Not mentioned
CWE
Product Name: tar and cpio utilities
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: Not mentioned
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
Not mentioned
Denial-of-Service Vulnerability in GNU tar and cpio utilities
The GNU tar and cpio utilities are prone to a denial-of-service vulnerability because of insecure use of the 'alloca()' function. Successfully exploiting this issue allows attackers to crash the affected utilities and possibly to execute code, but this has not been confirmed. GNU tar and cpio utilities share the same vulnerable code and are both affected. Other utilities sharing this code may also be affected.
Mitigation:
Not mentioned