NULL pointer dereference in Tar - CVE-2019-9923

 

NULL pointer dereference in Tar - CVE-2019-9923

Published: March 22, 2019


Vulnerability identifier: #VU18058
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9923
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dreference error in sparse.c in when parsing certain archives that have malformed extended headers. A remote attacker can perform a denial of service (DoS) attack.


Affected software

Tar
Amazon Linux AMI
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
Ubuntu
Opensuse
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
DataMosaix Private Cloud
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
tar (Ubuntu package)
tar
tar-backup-scripts
tar-rmt-debuginfo
tar-tests
tar-tests-debuginfo
tar-rmt
tar-doc
tar-lang
tar-debuginfo
tar-debugsource
VMware Tanzu Operations Manager
Junos cRPD

How to mitigate CVE-2019-9923

Install update from vendor's website.

Tar - update to 1.32
DataMosaix Private Cloud - update to 7.09
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.1, 4.8.0
Netcool Operations Insight - update to 1.6.8
tar (Ubuntu package) - addressed in versions 1.26-4ubuntu1.2, 1.28-2.1ubuntu0.2, 1.29b-2ubuntu0.2, 1.30+dfsg-7ubuntu0.20.04.1, 1.30+dfsg-7ubuntu0.20.10.1
tar - update to 1.26-31.24
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-rmt-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
tar-rmt - update to 1.34-150000.3.12.1
tar - update to 1.34-150000.3.12.1
tar-doc - update to 1.34-150000.3.12.1
tar-lang - update to 1.34-150000.3.12.1
tar-debuginfo - update to 1.34-150000.3.12.1
tar-debugsource - update to 1.34-150000.3.12.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.28, 2.9.16, 2.10.5
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins