CVE-2013-4397
Publication date 17 October 2013
Last updated 24 July 2024
Ubuntu priority
Description
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libtar | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
Patch details
| Package | Patch details |
|---|---|
| libtar |
|