Infinite loop in Tar - CVE-2018-20482
Published: January 2, 2019 / Updated: March 22, 2019
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the application mishandles file shrinkage during read access when --sparse is used. A local attacker can trigger infinite read loop in sparse_dump_region in sparse.c by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root) and cause denial of service conditions.
Affected software
Arch Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Ubuntu
Opensuse
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
tar (Alpine package)
tar (Ubuntu package)
tar-backup-scripts
tar-debuginfo
tar
tar-debugsource
tar-doc
tar-lang
tar-rmt
tar-rmt-debuginfo
tar-tests
tar-tests-debuginfo
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2018-20482
tar (Alpine package) - update to 1.31-r0
tar (Ubuntu package) - addressed in versions 1.26-4ubuntu1.2, 1.28-2.1ubuntu0.2, 1.29b-2ubuntu0.2, 1.30+dfsg-7ubuntu0.20.04.1, 1.30+dfsg-7ubuntu0.20.10.1
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-debuginfo - update to 1.34-150000.3.12.1
tar - update to 1.34-150000.3.12.1
tar-debugsource - update to 1.34-150000.3.12.1
tar-doc - update to 1.34-150000.3.12.1
tar-lang - update to 1.34-150000.3.12.1
tar-rmt - update to 1.34-150000.3.12.1
tar-rmt-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.28, 2.9.16, 2.10.5
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
IBM Cloud Transformation Advisor - update to 3.10.0
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Denial of service in GNU Tar
- Arch Linux update for tar
- OpenSUSE Linux update for tar
- Gentoo update for Tar
- Infinite loop in tar (Alpine package)
- Multiple vulnerabilities in VMware Tanzu Products
- Ubuntu update for tar
- SUSE update for tar
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Cloud Transformation Advisor