CVE-2021-33643

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
10/08/2022
Last modified:
03/11/2025

Description

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:feep:libtar:*:*:*:*:*:*:*:* 1.2.21 (excluding)
cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:*
cpe:2.3:o:openatom:openeuler:20.03:sp3:*:*:lts:*:*:*
cpe:2.3:o:openatom:openeuler:22.03:*:*:*:lts:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools