CVE-2010-0624

Description

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.474

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2001-1267,CVE-2002-1216,CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.19Windows
Multiple Vulnerabilities are affected in GNU Tar 1.13.25Windows
Multiple Vulnerabilities are affected in GNU Tar 1.15.1Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.14Windows
Vulnerabilities CVE-2006-0300,CVE-2010-0624 are affected in GNU Tar 1.14.1Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15Windows
Vulnerabilities CVE-2006-0300,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15.90Windows
Vulnerabilities CVE-2006-6097,CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.16Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.11Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.14Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.16Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.17Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.18Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.13.5Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624 are affected in GNU Tar 1.14.90Windows
Vulnerabilities CVE-2007-4131,CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.15.91Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.16.1Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.17Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.18Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.19Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.20Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.21Windows
Vulnerabilities CVE-2010-0624,CVE-2016-6321 are affected in GNU Tar 1.22Windows
(RHSA-2010:0141) Moderate: tar security update tar-1.15.1-23.0.1.el5_4.2.i386.rpmLinux
(RHSA-2010:0141) Moderate: tar security update tar-1.15.1-23.0.1.el5_4.2.x86_64.rpmLinux
(RHSA-2010:0144) Moderate: cpio security update cpio-2.6-23.el5_4.1.i386.rpmLinux
(RHSA-2010:0144) Moderate: cpio security update cpio-2.6-23.el5_4.1.x86_64.rpmLinux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2010-0624)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234