CVE-2019-9923

HIGH

GNU Tar < 1.32 - Denial of Service via Malformed Extended Header Parsing

Title source: llm
STIX 2.1

Description

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

References (6)

Core 6
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241
Permissions Required, Third Party Advisory x_refsource_misc
http://savannah.gnu.org/bugs/?55369
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html

Scores

CVSS v3 7.5
EPSS 0.0040
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (2)
gnu/tar < 1.32
opensuse/leap 15.0
Published Mar 22, 2019
Tracked Since Feb 18, 2026