Infinite loop in Tar - CVE-2018-20482

 

Infinite loop in Tar - CVE-2018-20482

Published: January 2, 2019 / Updated: March 22, 2019


Vulnerability identifier: #VU16782
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20482
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the application mishandles file shrinkage during read access when --sparse is used. A local attacker can trigger infinite read loop in sparse_dump_region in sparse.c by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root) and cause denial of service conditions.


Affected software

Tar
Arch Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Ubuntu
Opensuse
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
tar (Alpine package)
tar (Ubuntu package)
tar-backup-scripts
tar-debuginfo
tar
tar-debugsource
tar-doc
tar-lang
tar-rmt
tar-rmt-debuginfo
tar-tests
tar-tests-debuginfo
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2018-20482

Install update from vendor's website.

Tar - update to 1.31
tar (Alpine package) - update to 1.31-r0
tar (Ubuntu package) - addressed in versions 1.26-4ubuntu1.2, 1.28-2.1ubuntu0.2, 1.29b-2ubuntu0.2, 1.30+dfsg-7ubuntu0.20.04.1, 1.30+dfsg-7ubuntu0.20.10.1
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-debuginfo - update to 1.34-150000.3.12.1
tar - update to 1.34-150000.3.12.1
tar-debugsource - update to 1.34-150000.3.12.1
tar-doc - update to 1.34-150000.3.12.1
tar-lang - update to 1.34-150000.3.12.1
tar-rmt - update to 1.34-150000.3.12.1
tar-rmt-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.28, 2.9.16, 2.10.5
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
IBM Cloud Transformation Advisor - update to 3.10.0
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins