Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title libtar: Arbitraty code execution
Informations
Name GLSA-201402-19 First vendor Publication 2014-02-21
Vendor Gentoo Last vendor Modification 2014-02-21
Severity (Vendor) Normal Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Synopsis

A buffer overflow in libtar might allow remote attackers to execute arbitrary code or cause a Denial of Service condition.

Background

libtar is a C library for manipulating POSIX tar files.

Description

An integer overflow error within the â

Original Source

Url : http://security.gentoo.org/glsa/glsa-201402-19.xml

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-189 Numeric Errors (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:20857
 
Oval ID: oval:org.mitre.oval:def:20857
Title: DSA-2817-1 libtar - Multiple integer overflows
Description: Timo Warns reported multiple integer overflow vulnerabilities in libtar, a library for manipulating tar archives, which can result in the execution of arbitrary code.
Family: unix Class: patch
Reference(s): DSA-2817-1
CVE-2013-4397
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/Linux 7
Debian GNU/kFreeBSD 6.0
Debian GNU/kFreeBSD 7
Product(s): libtar
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27463
 
Oval ID: oval:org.mitre.oval:def:27463
Title: DEPRECATED: ELSA-2013-1418 -- libtar security update (moderate)
Description: [1.2.11-17.el6_4.1] - fix CVE-2013-4397: buffer overflows by expanding a specially-crafted archive
Family: unix Class: patch
Reference(s): ELSA-2013-1418
CVE-2013-4397
Version: 4
Platform(s): Oracle Linux 6
Product(s): libtar
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 9
Os 1

Nessus® Vulnerability Scanner

Date Description
2016-02-05 Name : The remote device is missing a vendor-supplied security patch.
File : f5_bigip_SOL16015326.nasl - Type : ACT_GATHER_INFO
2014-02-23 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201402-19.nasl - Type : ACT_GATHER_INFO
2013-12-16 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2817.nasl - Type : ACT_GATHER_INFO
2013-11-11 Name : The remote Fedora host is missing a security update.
File : fedora_2013-18877.nasl - Type : ACT_GATHER_INFO
2013-10-21 Name : The remote Fedora host is missing a security update.
File : fedora_2013-18808.nasl - Type : ACT_GATHER_INFO
2013-10-20 Name : The remote Fedora host is missing a security update.
File : fedora_2013-18785.nasl - Type : ACT_GATHER_INFO
2013-10-20 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-253.nasl - Type : ACT_GATHER_INFO
2013-10-13 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2013-1418.nasl - Type : ACT_GATHER_INFO
2013-10-11 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2013-1418.nasl - Type : ACT_GATHER_INFO
2013-10-11 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-1418.nasl - Type : ACT_GATHER_INFO
2013-10-11 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20131010_libtar_on_SL6_x.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-23 13:21:08
  • Multiple Updates
2014-02-21 09:18:46
  • First insertion