NULL pointer dereference in Tar - CVE-2019-9923
Published: March 22, 2019
Vulnerability identifier: #VU18058
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9923
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in sparse.c in when parsing certain archives that have malformed extended headers. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Tar
Amazon Linux AMI
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
Ubuntu
Opensuse
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
DataMosaix Private Cloud
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
tar (Ubuntu package)
tar
tar-backup-scripts
tar-rmt-debuginfo
tar-tests
tar-tests-debuginfo
tar-rmt
tar-doc
tar-lang
tar-debuginfo
tar-debugsource
VMware Tanzu Operations Manager
Junos cRPD
Amazon Linux AMI
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
Ubuntu
Opensuse
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
DataMosaix Private Cloud
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
tar (Ubuntu package)
tar
tar-backup-scripts
tar-rmt-debuginfo
tar-tests
tar-tests-debuginfo
tar-rmt
tar-doc
tar-lang
tar-debuginfo
tar-debugsource
VMware Tanzu Operations Manager
Junos cRPD
How to mitigate CVE-2019-9923
Install update from vendor's website.
Tar - update to 1.32
DataMosaix Private Cloud - update to 7.09
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.1, 4.8.0
Netcool Operations Insight - update to 1.6.8
tar (Ubuntu package) - addressed in versions 1.26-4ubuntu1.2, 1.28-2.1ubuntu0.2, 1.29b-2ubuntu0.2, 1.30+dfsg-7ubuntu0.20.04.1, 1.30+dfsg-7ubuntu0.20.10.1
tar - update to 1.26-31.24
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-rmt-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
tar-rmt - update to 1.34-150000.3.12.1
tar - update to 1.34-150000.3.12.1
tar-doc - update to 1.34-150000.3.12.1
tar-lang - update to 1.34-150000.3.12.1
tar-debuginfo - update to 1.34-150000.3.12.1
tar-debugsource - update to 1.34-150000.3.12.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.28, 2.9.16, 2.10.5
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
DataMosaix Private Cloud - update to 7.09
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.1, 4.8.0
Netcool Operations Insight - update to 1.6.8
tar (Ubuntu package) - addressed in versions 1.26-4ubuntu1.2, 1.28-2.1ubuntu0.2, 1.29b-2ubuntu0.2, 1.30+dfsg-7ubuntu0.20.04.1, 1.30+dfsg-7ubuntu0.20.10.1
tar - update to 1.26-31.24
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-rmt-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
tar-rmt - update to 1.34-150000.3.12.1
tar - update to 1.34-150000.3.12.1
tar-doc - update to 1.34-150000.3.12.1
tar-lang - update to 1.34-150000.3.12.1
tar-debuginfo - update to 1.34-150000.3.12.1
tar-debugsource - update to 1.34-150000.3.12.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.28, 2.9.16, 2.10.5
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- NULL pointer dereference in GNU Tar
- OpenSUSE Linux update for tar
- Multiple vulnerabilities in VMware Tanzu Products
- Ubuntu update for tar
- NULL pointer dereference in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- SUSE update for tar
- Amazon Linux AMI update for tar
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Rockwell Automation DataMosaix Private Cloud
- Denial of service in F5OS GNU Tar coponent