Executive Summary

Summary
TitleNew tar packages fix arbitrary code execution
Informations
NameDSA-987First vendor Publication2006-03-07
VendorDebianLast vendor Modification2006-03-07
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P)
Cvss Base Score5.1Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityHigh
Cvss Expoit Score4.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Jim Meyering discovered several buffer overflows in GNU tar, which may lead to the execution of arbitrary code through specially crafted tar archives.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 1.14-2.1.

For the unstable distribution (sid) this problem has been fixed in version 1.15.1-3.

We recommend that you upgrade your tar package.

Original Source

Url : http://www.debian.org/security/2006/dsa-987

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:9295
 
Oval ID: oval:org.mitre.oval:def:9295
Title: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Description: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-0300
Version: 5
Platform(s): Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:6094
 
Oval ID: oval:org.mitre.oval:def:6094
Title: Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)
Description: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-0300
Version: 1
Platform(s): Sun Solaris 9
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:5993
 
Oval ID: oval:org.mitre.oval:def:5993
Title: Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)
Description: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-0300
Version: 1
Platform(s): Sun Solaris 9
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:5978
 
Oval ID: oval:org.mitre.oval:def:5978
Title: Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)
Description: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-0300
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:5252
 
Oval ID: oval:org.mitre.oval:def:5252
Title: Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)
Description: Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-0300
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application5

Open Source Vulnerability Database (OSVDB)

idDescription
23371GNU tar PAX Extended Headers Handling Overflow