Vulnerability CVE-2021-33643: Information

Description

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

Severity: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Published: Aug. 10, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-125

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:feep:libtar:*:*:*:*:*:*:*:*
      End excliding
      1.2.21

      Configuration 2

      cpe:2.3:o:huawei:openeuler:20.03:sp3:*:*:lts:*:*:*

      cpe:2.3:o:huawei:openeuler:20.03:sp1:*:*:lts:*:*:*

      cpe:2.3:o:huawei:openeuler:22.03:*:*:*:lts:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*