Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-4397

Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.3%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2013-4397
  • Feep » Libtar » Version: N/A
    cpe:2.3:a:feep:libtar:-
  • Feep » Libtar » Version: 1.2.11
    cpe:2.3:a:feep:libtar:1.2.11
  • Feep » Libtar » Version: 1.2.13
    cpe:2.3:a:feep:libtar:1.2.13
  • Feep » Libtar » Version: 1.2.14
    cpe:2.3:a:feep:libtar:1.2.14
  • Feep » Libtar » Version: 1.2.15
    cpe:2.3:a:feep:libtar:1.2.15
  • Feep » Libtar » Version: 1.2.16
    cpe:2.3:a:feep:libtar:1.2.16
  • Feep » Libtar » Version: 1.2.17
    cpe:2.3:a:feep:libtar:1.2.17
  • Feep » Libtar » Version: 1.2.18
    cpe:2.3:a:feep:libtar:1.2.18
  • Feep » Libtar » Version: 1.2.19
    cpe:2.3:a:feep:libtar:1.2.19
  • Redhat » Enterprise Linux » Version: 6.0
    cpe:2.3:o:redhat:enterprise_linux:6.0


Contact Us

Shodan ® - All rights reserved