Lucene search

K
cve[email protected]CVE-2010-0624
HistoryMar 15, 2010 - 1:28 p.m.

CVE-2010-0624

2010-03-1513:28:25
CWE-119
web.nvd.nist.gov
40
cve-2010-0624
buffer overflow
gnu tar
memory corruption
denial of service
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.5%

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

Affected configurations

NVD
Node
gnucpioRangeโ‰ค2.10
OR
gnucpioMatch1.0
OR
gnucpioMatch1.1
OR
gnucpioMatch1.2
OR
gnucpioMatch1.3
OR
gnucpioMatch2.4-2
OR
gnucpioMatch2.5
OR
gnucpioMatch2.5.90
OR
gnucpioMatch2.6
OR
gnucpioMatch2.7
OR
gnucpioMatch2.8
OR
gnucpioMatch2.9
OR
gnutarRangeโ‰ค1.22
OR
gnutarMatch1.13
OR
gnutarMatch1.13.5
OR
gnutarMatch1.13.11
OR
gnutarMatch1.13.14
OR
gnutarMatch1.13.16
OR
gnutarMatch1.13.17
OR
gnutarMatch1.13.18
OR
gnutarMatch1.13.19
OR
gnutarMatch1.13.25
OR
gnutarMatch1.14
OR
gnutarMatch1.14.1
OR
gnutarMatch1.14.90
OR
gnutarMatch1.15
OR
gnutarMatch1.15.1
OR
gnutarMatch1.15.90
OR
gnutarMatch1.15.91
OR
gnutarMatch1.16
OR
gnutarMatch1.16.1
OR
gnutarMatch1.17
OR
gnutarMatch1.18
OR
gnutarMatch1.19
OR
gnutarMatch1.20
OR
gnutarMatch1.21

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.5%