Vulnerability Name:

CVE-2021-20193 (CCN-198956)

Assigned:2020-11-13
Published:2020-11-13
Updated:2021-06-03
Summary:A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
CWE-401
CWE-125
CWE-401
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-20193

Source: CCN
Type: Red Hat Bugzilla – Bug 1917565
(CVE-2021-20193) - CVE-2021-20193 tar: Memory leak in read_header() in list.c

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1917565

Source: XF
Type: UNKNOWN
tar-cve202120193-dos(198956)

Source: CCN
Type: Tar GIT Repository
Fix memory leak in read_header

Source: MISC
Type: Mailing List, Patch, Third Party Advisory
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777

Source: MISC
Type: Issue Tracking, Patch, Vendor Advisory
https://savannah.gnu.org/bugs/?59897

Source: GENTOO
Type: Third Party Advisory
GLSA-202105-29

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-20193

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:tar:*:*:*:*:*:*:*:* (Version <= 1.33)

  • Configuration CCN 1:
  • cpe:/a:gnu:tar:1.33:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7815
    P
    tar-1.34-150000.3.31.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3209
    P
    libmms0-0.6.2-15.8 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3588
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94700
    P
    libruby2_5-2_5-2.5.9-150000.4.23.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94839
    P
    tar-1.34-150000.3.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:318
    P
    tar-1.30-3.6.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:367
    P
    tar-1.34-150000.3.12.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:93293
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:880
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:93605
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:42277
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:94020
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:94441
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:42376
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:119089
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:93451
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:93806
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:93133
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:94232
    P
    (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:42181
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:101620
    P
    Security update for tar (Moderate) (in QA)
    2022-04-12
    oval:org.opensuse.security:def:5996
    P
    Security update for python3 (Moderate)
    2022-03-30
    oval:org.opensuse.security:def:102257
    P
    Security update for qemu (Important)
    2022-03-22
    oval:org.opensuse.security:def:113481
    P
    tar-1.34-5.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:101413
    P
    apache-commons-beanutils-1.9.4-1.68 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101094
    P
    tar-1.30-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62336
    P
    tar-1.30-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72077
    P
    tar-1.30-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1247
    P
    tar-1.30-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:111297
    P
    Security update for tar (Low)
    2021-04-02
    oval:org.opensuse.security:def:67085
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:5985
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:76153
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:94012
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:33104
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:97354
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:60486
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:94434
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:108923
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:117593
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:43937
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:34663
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:93444
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:93797
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:39507
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:95544
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:45353
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:94223
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:42165
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:100388
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:64677
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:73799
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:40923
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:87568
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:58927
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:93600
    P
    (Low)
    2021-03-29
    oval:org.opensuse.security:def:108079
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:100721
    P
    (Low)
    2021-03-29
    BACK
    gnu tar *
    gnu tar 1.33