Advisories ยป MGASA-2023-0079

Updated tar packages fix security vulnerability

Publication date: 01 Mar 2023
Modification date: 01 Mar 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-48303

Description

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use
of uninitialized memory for a conditional jump. Exploitation to change the
flow of control has not been demonstrated. The issue occurs in from_header
in list.c via a V7 archive in which mtime has approximately 11 whitespace
characters. (CVE-2022-48303)
                

References

SRPMS

8/core