Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-48303

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.9%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2022-48303
  • Gnu » Tar » Version: N/A
    cpe:2.3:a:gnu:tar:-
  • Gnu » Tar » Version: 1.11
    cpe:2.3:a:gnu:tar:1.11
  • Gnu » Tar » Version: 1.11.1
    cpe:2.3:a:gnu:tar:1.11.1
  • Gnu » Tar » Version: 1.11.8
    cpe:2.3:a:gnu:tar:1.11.8
  • Gnu » Tar » Version: 1.12
    cpe:2.3:a:gnu:tar:1.12
  • Gnu » Tar » Version: 1.13
    cpe:2.3:a:gnu:tar:1.13
  • Gnu » Tar » Version: 1.13.11
    cpe:2.3:a:gnu:tar:1.13.11
  • Gnu » Tar » Version: 1.13.14
    cpe:2.3:a:gnu:tar:1.13.14
  • Gnu » Tar » Version: 1.13.16
    cpe:2.3:a:gnu:tar:1.13.16
  • Gnu » Tar » Version: 1.13.17
    cpe:2.3:a:gnu:tar:1.13.17
  • Gnu » Tar » Version: 1.13.18
    cpe:2.3:a:gnu:tar:1.13.18
  • Gnu » Tar » Version: 1.13.19
    cpe:2.3:a:gnu:tar:1.13.19
  • Gnu » Tar » Version: 1.13.25
    cpe:2.3:a:gnu:tar:1.13.25
  • Gnu » Tar » Version: 1.13.5
    cpe:2.3:a:gnu:tar:1.13.5
  • Gnu » Tar » Version: 1.14
    cpe:2.3:a:gnu:tar:1.14
  • Gnu » Tar » Version: 1.14.1
    cpe:2.3:a:gnu:tar:1.14.1
  • Gnu » Tar » Version: 1.14.90
    cpe:2.3:a:gnu:tar:1.14.90
  • Gnu » Tar » Version: 1.15
    cpe:2.3:a:gnu:tar:1.15
  • Gnu » Tar » Version: 1.15.1
    cpe:2.3:a:gnu:tar:1.15.1
  • Gnu » Tar » Version: 1.15.90
    cpe:2.3:a:gnu:tar:1.15.90
  • Gnu » Tar » Version: 1.15.91
    cpe:2.3:a:gnu:tar:1.15.91
  • Gnu » Tar » Version: 1.16
    cpe:2.3:a:gnu:tar:1.16
  • Gnu » Tar » Version: 1.16.1
    cpe:2.3:a:gnu:tar:1.16.1
  • Gnu » Tar » Version: 1.17
    cpe:2.3:a:gnu:tar:1.17
  • Gnu » Tar » Version: 1.18
    cpe:2.3:a:gnu:tar:1.18
  • Gnu » Tar » Version: 1.19
    cpe:2.3:a:gnu:tar:1.19
  • Gnu » Tar » Version: 1.20
    cpe:2.3:a:gnu:tar:1.20
  • Gnu » Tar » Version: 1.21
    cpe:2.3:a:gnu:tar:1.21
  • Gnu » Tar » Version: 1.22
    cpe:2.3:a:gnu:tar:1.22
  • Gnu » Tar » Version: 1.23
    cpe:2.3:a:gnu:tar:1.23
  • Gnu » Tar » Version: 1.24
    cpe:2.3:a:gnu:tar:1.24
  • Gnu » Tar » Version: 1.25
    cpe:2.3:a:gnu:tar:1.25
  • Gnu » Tar » Version: 1.26
    cpe:2.3:a:gnu:tar:1.26
  • Gnu » Tar » Version: 1.27
    cpe:2.3:a:gnu:tar:1.27
  • Gnu » Tar » Version: 1.27.1
    cpe:2.3:a:gnu:tar:1.27.1
  • Gnu » Tar » Version: 1.28
    cpe:2.3:a:gnu:tar:1.28
  • Gnu » Tar » Version: 1.29
    cpe:2.3:a:gnu:tar:1.29
  • Gnu » Tar » Version: 1.30
    cpe:2.3:a:gnu:tar:1.30
  • Gnu » Tar » Version: 1.31
    cpe:2.3:a:gnu:tar:1.31
  • Gnu » Tar » Version: 1.32
    cpe:2.3:a:gnu:tar:1.32
  • Gnu » Tar » Version: 1.33
    cpe:2.3:a:gnu:tar:1.33
  • Gnu » Tar » Version: 1.34
    cpe:2.3:a:gnu:tar:1.34
  • Fedoraproject » Fedora » Version: 37
    cpe:2.3:o:fedoraproject:fedora:37
  • Fedoraproject » Fedora » Version: 38
    cpe:2.3:o:fedoraproject:fedora:38


Contact Us

Shodan ® - All rights reserved