Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-4476

38
FAUCET Score

CVE-2007-4476 describes a buffer overflow vulnerability within the safer_name_suffix function in GNU tar, impacting various distributions including Canonical and Debian Linux. This flaw carries a CVSS score of 7.5, indicating a high severity due to its network-based attack vector and low attack complexity, potentially leading to a "crashing stack" and resulting in partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation in the wild, a denial-of-service exploit for GNU TAR 1.15.91 / CPIO 2.5.90 exists on ExploitDB, and the vulnerability has minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.19CPE matchmatch criteria
cpe:2.3:a:gnu:tar:*:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
14.90%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-30766 · Nov 14, 2007
This CVE's current EPSS score of 0.1490 is in the 95th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: tar-0:1.14-13.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tar-2:1.15.1-23.0.1.el5_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: cpio-0:2.6-23.el5_4.1
View patch

Vendor Advisories (1)

redhatCVE-2007-4476Low

tar/cpio stack crashing in safer_name_suffix

Aug 17, 2007

References

bugs.gentoo.org / show_bug.cgi
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/26674
PatchThird Party Advisory
secunia.com / advisories/26987
Third Party Advisory
secunia.com / advisories/27331
Third Party Advisory
secunia.com / advisories/27453
Third Party Advisory
secunia.com / advisories/27514
Third Party Advisory
secunia.com / advisories/27681
Third Party Advisory
secunia.com / advisories/27857
Third Party Advisory
secunia.com / advisories/28255
Third Party Advisory
secunia.com / advisories/29968
Third Party Advisory
secunia.com / advisories/32051
Third Party Advisory
secunia.com / advisories/33567
Third Party Advisory
secunia.com / advisories/39008
Third Party Advisory
security.gentoo.org / glsa/glsa-200711-18.xml
Third Party Advisory
issues.rpath.com / browse/RPL-1861
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7114
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8599
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9336
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
redhat.com / archives/fedora-package-announce/2007-November/msg00073.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2007-October/msg00370.html
Third Party Advisory
debian.org / security/2007/dsa-1438
Third Party Advisory
debian.org / security/2008/dsa-1566
Third Party Advisory
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
novell.com / linux/security/advisories/2007_18_sr.html
Broken Link
novell.com / linux/security/advisories/2007_19_sr.html
Broken Link
redhat.com / support/errata/RHSA-2010-0141.html
Third Party Advisory
redhat.com / support/errata/RHSA-2010-0144.html
Third Party Advisory
securityfocus.com / bid/26445
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-650-1
Third Party Advisory
ubuntu.com / usn/usn-709-1
Third Party Advisory
vupen.com / english/advisories/2010/0628
Permissions Required
vupen.com / english/advisories/2010/0629
Permissions Required