CVE-2021-33643
libtar, openeuler, fedora
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
- CVSS
- 9.1
- EPSS
- 1.35% 68.8% percentile
- CISA KEV
- Not listed
- Published
- 2022.08.11