CVE Vulnerabilities

CVE-2023-39804

Published: Mar 27, 2024 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Affected Software

NameVendorStart VersionEnd Version
TarGnu*1.35 (excluding)
TarUbuntubionic*
TarUbuntudevel*
TarUbuntuesm-infra-legacy/trusty*
TarUbuntuesm-infra/bionic*
TarUbuntuesm-infra/focal*
TarUbuntuesm-infra/xenial*
TarUbuntufocal*
TarUbuntujammy*
TarUbuntulunar*
TarUbuntumantic*
TarUbuntutrusty*
TarUbuntutrusty/esm*
TarUbuntuupstream*
TarUbuntuxenial*

References