Gnu

Tar

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 03.08.2026 15:34:36
  • Zuletzt bearbeitet 13.08.2026 16:09:33

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system...

  • EPSS 0.14%
  • Veröffentlicht 03.08.2026 14:51:41
  • Zuletzt bearbeitet 18.08.2026 16:36:55

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can creat...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 06.04.2026 15:17:27
  • Zuletzt bearbeitet 22.04.2026 20:08:59

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allo...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 11.07.2025 00:00:00
  • Zuletzt bearbeitet 02.11.2025 01:15:32

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extrac...

  • EPSS 0.28%
  • Veröffentlicht 27.03.2024 04:15:08
  • Zuletzt bearbeitet 04.11.2025 19:15:55

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Exploit
  • EPSS 1.48%
  • Veröffentlicht 30.01.2023 04:15:08
  • Zuletzt bearbeitet 27.03.2025 21:15:40

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archiv...

  • EPSS 1.09%
  • Veröffentlicht 26.03.2021 17:15:12
  • Zuletzt bearbeitet 05.05.2025 14:15:04

A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.

  • EPSS 3.03%
  • Veröffentlicht 22.03.2019 08:29:00
  • Zuletzt bearbeitet 06.08.2025 22:15:28

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 26.12.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:34

GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archive...

Exploit
  • EPSS 15.16%
  • Veröffentlicht 09.12.2016 22:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the ...