CVE-2022-48303

Source
https://cve.org/CVERecord?id=CVE-2022-48303
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48303.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48303
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (5)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (4)
openSUSE (1)
RHSA (3)
RLSA (2)
SUSE (2)
UBUNTU (1)
Related
Published
2023-01-30T04:15:08Z
Modified
2026-04-16T00:07:54Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48303.json"
unresolved_ranges
[
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "last_affected":  "1.34"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "last_affected":  "37"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "last_affected":  "38"
            }
        ]
    }
]