Denial of Service in GNU Tar Due to File Shrinkage Mismanagement
CVE-2018-20482

4.7MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
26 December 2018

Summary

A flaw in GNU Tar versions up to 1.30 can cause a denial of service when the '--sparse' option is employed. This vulnerability occurs due to improper handling of file shrinkage during read operations. If a file, intended for archiving by another user (such as during a system backup executed as root), is modified, it may lead to an infinite read loop. This issue allows local users to disrupt processes that rely on the integrity of the archived data, making it critical for systems using GNU Tar to implement appropriate fixes.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.