CVE-2022-48303 is a one-byte out-of-bounds read vulnerability in GNU Tar through version 1.34, specifically affecting Fedora and GNU Tar products. This issue occurs in the from_header function when processing V7 archives with approximately 11 whitespace characters in the mtime field, leading to the use of uninitialized memory for a conditional jump. Rated Medium severity (CVSS 5.5), it requires local access and user interaction (UI:R) to trigger, with a potential impact on availability (A:H) but no demonstrated control flow change. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.34CPE matchmatch criteria | cpe:2.3:a:gnu:tar:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-48303
Nov 12, 2024GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump
Jan 10, 2023tar: heap buffer overflow at from_header() in list.c via specially crafted checksum
Apr 30, 2022