{"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2023:0959","synopsis":"Moderate: tar security update","severity":"SEVERITY_MODERATE","topic":"An update is available for tar.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The GNU tar program can save multiple files in an archive and restore files from an archive.\n\nSecurity Fix(es):\n\n* tar: heap buffer overflow at from_header() in list.c via specially crafted checksum (CVE-2022-48303)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2149722","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2149722","description":""}],"cves":[{"name":"CVE-2022-48303","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-48303","cvss3ScoringVector":"CVSS:3.1\/AV:L\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","cvss3BaseScore":"7.8","cwe":"CWE-119"}],"references":[],"publishedAt":"2023-04-06T15:53:31.763565Z","rpms":{"Rocky Linux 9":{"nvras":["tar-2:1.34-6.el9_1.aarch64.rpm","tar-2:1.34-6.el9_1.ppc64le.rpm","tar-2:1.34-6.el9_1.s390x.rpm","tar-2:1.34-6.el9_1.src.rpm","tar-2:1.34-6.el9_1.x86_64.rpm","tar-debuginfo-2:1.34-6.el9_1.aarch64.rpm","tar-debuginfo-2:1.34-6.el9_1.ppc64le.rpm","tar-debuginfo-2:1.34-6.el9_1.s390x.rpm","tar-debuginfo-2:1.34-6.el9_1.x86_64.rpm","tar-debugsource-2:1.34-6.el9_1.aarch64.rpm","tar-debugsource-2:1.34-6.el9_1.ppc64le.rpm","tar-debugsource-2:1.34-6.el9_1.s390x.rpm","tar-debugsource-2:1.34-6.el9_1.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}

Rocky Linux: RLSA-2023:0959 tar security update

April 6, 2023
An update is available for tar. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Summary

An update is available for tar. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


The GNU tar program can save multiple files in an archive and restore files from an archive. Security Fix(es): * tar: heap buffer overflow at from_header() in list.c via specially crafted checksum (CVE-2022-48303) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

RPMs

tar-2:1.34-6.el9_1.aarch64.rpm

tar-2:1.34-6.el9_1.ppc64le.rpm

tar-2:1.34-6.el9_1.s390x.rpm

tar-2:1.34-6.el9_1.src.rpm

tar-2:1.34-6.el9_1.x86_64.rpm

tar-debuginfo-2:1.34-6.el9_1.aarch64.rpm

tar-debuginfo-2:1.34-6.el9_1.ppc64le.rpm

tar-debuginfo-2:1.34-6.el9_1.s390x.rpm

tar-debuginfo-2:1.34-6.el9_1.x86_64.rpm

tar-debugsource-2:1.34-6.el9_1.aarch64.rpm

tar-debugsource-2:1.34-6.el9_1.ppc64le.rpm

tar-debugsource-2:1.34-6.el9_1.s390x.rpm

tar-debugsource-2:1.34-6.el9_1.x86_64.rpm

References

No References

CVEs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48303

Severity
Name: RLSA-2023:0959
Affected Products: Rocky Linux 9

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2149722


Related News