CVE-2021-33644
10.08.2022, 20:15
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.Enginsight
Vendor | Product | Version |
---|---|---|
feep | libtar | 𝑥 < 1.2.21 |
openatom | openeuler | 20.03:sp1 |
openatom | openeuler | 20.03:sp3 |
openatom | openeuler | 22.03 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References