Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Tar和GNU Cpio远程堆溢出漏洞
Vulnerability Description
GNU Tar和GNU Cpio都是流行的用于管理档案文件的程序。 GNU Tar/Cpio的rmt客户端的lib/rtapelib.c文件的rmt_read__函数存在堆溢出漏洞。在for循环中,rmt_read__函数从服务器将status字节读入到缓冲区时,但没有检查status是否小于或等于length参数所指定的缓冲区长度,因此恶意rmt服务器可以覆盖缓冲区后堆上数据。
CVSS Information
N/A
Vulnerability Type
N/A