CVE-2007-4476

GNU tar < 1.19 - Buffer Overflow in safer_name_suffix

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4476. PoCs published by Dmitry V. Levin.

AI-analyzed exploit summary This exploit reproduces a stack overflow in GNU tar and cpio utilities by leveraging insecure use of the 'alloca()' function in the 'safer_name_suffix()' function. It creates a long string of '../' sequences to trigger the vulnerability, potentially causing a denial-of-service or arbitrary code execution.

Description

Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dmitry V. Levin · cdoslinux
https://www.exploit-db.com/exploits/30766

This exploit reproduces a stack overflow in GNU tar and cpio utilities by leveraging insecure use of the 'alloca()' function in the 'safer_name_suffix()' function. It creates a long string of '../' sequences to trigger the vulnerability, potentially causing a denial-of-service or arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: GNU tar and cpio utilities (versions sharing vulnerable code)
No auth needed
Prerequisites: Access to the target system to execute the binary · Ability to create a malicious tar file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (37)

Core 37
Core References
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27331
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32051
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29968
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_19_sr.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27681
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26445
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27453
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1566
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27514
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-709-1
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-1861
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0144.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1438
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:233
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00073.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27857
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0629
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200711-18.xml
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:197
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26987
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_18_sr.html
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0628
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0141.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28255
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33567
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39008
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-650-1
Patch, Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26674
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=280961
Third Party Advisory x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=196978

Scores

EPSS 0.1490
EPSS Percentile 96.3%

Details

CWE
CWE-119
Status published
Products (6)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 7.04
canonical/ubuntu_linux 7.10
debian/debian_linux 3.1
debian/debian_linux 4.0
gnu/tar < 1.19
Published Sep 05, 2007
Tracked Since Feb 18, 2026