Memory leak in Tar - CVE-2021-20193

 

Memory leak in Tar - CVE-2021-20193

Published: February 28, 2021 / Updated: February 21, 2023


Vulnerability identifier: #VU50978
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20193
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within the read_header() function in list.c. A remote attacker can pass specially crafted archive to the application and force it to leak memory, which eventually results in a denial of service condition.


Affected software

Tar
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
cflinuxfs3
Robotic Process Automation for Cloud Pak
tar (Ubuntu package)
tar-lang
tar-debugsource
tar-debuginfo
tar
tar-rmt
tar-rmt-debuginfo
tar-help
tar-doc
tar-backup-scripts
tar-tests-debuginfo
tar-tests
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2021-20193

Install update from vendor's website.

Tar - update to 1.34
cflinuxfs3 - update to 0.279.0
tar (Ubuntu package) - addressed in versions UA Infra or UA Desktop, 1.29b-2ubuntu0.3, 1.30+dfsg-7ubuntu0.20.04.2
tar-lang - addressed in versions 1.27.1-15.9.1, 1.30-3.6.1, 1.34-150000.3.12.1
tar-debugsource - addressed in versions 1.27.1-15.9.1, 1.30-3.6.1, 1.34-150000.3.12.1
tar-debuginfo - addressed in versions 1.27.1-15.9.1, 1.30-3.6.1, 1.34-150000.3.12.1
tar - addressed in versions 1.27.1-15.9.1, 1.30-3.6.1, 1.34-150000.3.12.1
tar-rmt - addressed in versions 1.30-3.6.1, 1.34-150000.3.12.1
tar-rmt-debuginfo - addressed in versions 1.30-3.6.1, 1.34-150000.3.12.1
tar-help - update to 1.32-2
tar-debuginfo - update to 1.32-2
tar-debugsource - update to 1.32-2
tar - update to 1.32-2
tar-doc - update to 1.34-150000.3.12.1
tar-backup-scripts - update to 1.34-150000.3.12.1
tar-tests-debuginfo - update to 1.34-150000.3.12.1
tar-tests - update to 1.34-150000.3.12.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins