GNU
GNU TAR: vulnerabilidades y CVE
GNU TAR tiene 23 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53542 | Alta (8.8) | 0.66% | — | 19 ago 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes selected file… |
| CVE-2026-18477 | Media (4.4) | 0.08% | — | 3 ago 2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the… |
| CVE-2026-18508 | Media (4.4) | 0.14% | — | 3 ago 2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working… |
| CVE-2026-12565 | Media (5.3) | 0.21% | — | 17 jun 2026 | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While… |
| CVE-2026-5704 | Media (5.5) | 0.40% | — | 6 abr 2026 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction… |
| CVE-2025-58183 | Media (4.3) | 0.44% | — | 29 oct 2025 | tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an… |
| CVE-2025-45582 | Media (4.1) | 0.49% | — | 11 jul 2025 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory.… |
| CVE-2023-39804 | Media (6.2) | 0.28% | — | 27 mar 2024 | In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c. |
| CVE-2022-48303 | Media (5.5) | 1.5% | — | 30 ene 2023 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in… |
| CVE-2021-20193 | Baja (3.3) | 1.1% | — | 26 mar 2021 | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability… |
| CVE-2019-9923 | Alta (7.5) | 3.0% | — | 22 mar 2019 | pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers. |
| CVE-2018-20482 | Media (4.7) | 0.53% | — | 26 dic 2018 | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file… |
| CVE-2016-6321 | Alta (7.5) | 16% | — | 9 dic 2016 | Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related… |
| CVE-2010-0624 | Media (6.8) | 4.7% | — | 15 mar 2010 | Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory… |
| CVE-2007-4476 | Alta (7.5) | 15% | — | 5 sept 2007 | Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." |
| CVE-2007-4131 | Media (6.8) | 2.7% | — | 25 ago 2007 | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in… |
| CVE-2006-6097 | Media (4) | 11% | — | 24 nov 2006 | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled… |
| CVE-2006-0300 | Media (5.1) | 5.2% | — | 24 feb 2006 | Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers. |
| CVE-2005-1918 | Baja (2.6) | 2.9% | — | 31 dic 2005 | The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files… |
| CVE-2005-2541 | Alta (10) | 4.0% | — | 10 ago 2005 | Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. |
| CVE-2002-1216 | Media (5) | 1.6% | — | 28 oct 2002 | GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check. |
| CVE-2002-0399 | Media (5) | 3.6% | — | 10 oct 2002 | Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which… |
| CVE-2001-1267 | Baja (2.1) | 1.1% | — | 12 jul 2001 | Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot). |