Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-39804

Published: December 1, 2023Last modified: December 1, 2023

Description

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Severity score breakdown

ParameterValue
Base score6.2
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTStarFixed (1.34-r3)
StreamtarNot affected (1.35-r2)

References

ON THIS PAGE