Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24021
HistoryApr 10, 2020 - 12:44 a.m.

Arbitrary Code Execution

2020-04-1000:44:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.013

Percentile

85.9%

tar is vulnerable to arbitrary code execution. The vulnerability exists as a heap-based buffer overflow flaw was found in the way tar expanded archive files. If a user were tricked into expanding a specially-crafted archive, it could cause the tar executable to crash or execute arbitrary code with the privileges of the user running tar.

References