Vulnerability Description
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Cpio | <= 2.10 |
| Gnu | Tar | <= 1.22 |
Related Weaknesses (CWE)
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.html
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
- http://osvdb.org/62950
- http://secunia.com/advisories/38869
- http://secunia.com/advisories/38988
- http://secunia.com/advisories/39008
- http://security.gentoo.org/glsa/glsa-201111-11.xml
- http://www.agrs.tu-berlin.de/index.php?id=78327Exploit
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:065
FAQ
What is CVE-2010-0624?
CVE-2010-0624 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of s...
How severe is CVE-2010-0624?
CVE-2010-0624 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0624?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Cpio, Gnu Tar.