CVE-2010-0624 describes a heap-based buffer overflow in the rmt client functionality of GNU tar before 1.23 and GNU cpio before 2.11. This vulnerability allows a malicious remote rmt server to cause a denial of service through memory corruption or potentially execute arbitrary code. The attack requires an attacker-controlled rmt server and a victim using a vulnerable client, with a CVSS score of 6.8 indicating moderate severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:1.0:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:1.1:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:1.2:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:gnu:cpio:1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.