Vulnerability Description
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Tar | < 1.19 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=196978Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://secunia.com/advisories/26674PatchThird Party Advisory
- http://secunia.com/advisories/26987Third Party Advisory
- http://secunia.com/advisories/27331Third Party Advisory
- http://secunia.com/advisories/27453Third Party Advisory
- http://secunia.com/advisories/27514Third Party Advisory
- http://secunia.com/advisories/27681Third Party Advisory
- http://secunia.com/advisories/27857Third Party Advisory
- http://secunia.com/advisories/28255Third Party Advisory
- http://secunia.com/advisories/29968Third Party Advisory
- http://secunia.com/advisories/32051Third Party Advisory
- http://secunia.com/advisories/33567Third Party Advisory
- http://secunia.com/advisories/39008Third Party Advisory
FAQ
What is CVE-2007-4476?
CVE-2007-4476 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
How severe is CVE-2007-4476?
CVE-2007-4476 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4476?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Tar, Debian Debian Linux, Canonical Ubuntu Linux.