Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 20.04 LTS: USN-5329-1 Critical: Tar Denial Of Service Issue

Ubuntu Large Esm H500
tar could be made to crash if it received specially crafted file.
=========================================================================Ubuntu Security Notice USN-5329-1
March 15, 2022

tar vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

tar could be made to crash if it received specially crafted
file.

Software Description:
- tar: GNU version of the tar archiving utility

Details:

It was discovered that tar incorrectly handled certain files.
An attacker could possibly use this issue to cause tar to crash,
resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   tar                             1.30+dfsg-7ubuntu0.20.04.2

Ubuntu 18.04 LTS:
   tar                             1.29b-2ubuntu0.3

Ubuntu 16.04 ESM:
   tar                             1.28-2.1ubuntu0.2+esm1

Ubuntu 14.04 ESM:
   tar                             1.27.1-1ubuntu0.1+esm2

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5329-1
   CVE-2021-20193

Package Information:
   https://launchpad.net/ubuntu/+source/tar/1.30+dfsg-7ubuntu0.20.04.2
   https://launchpad.net/ubuntu/+source/tar/1.29b-2ubuntu0.3

Ubuntu 20.04 LTS: USN-5329-1 Critical: Tar Denial Of Service Issue

ubuntu
Calendar Grey March 15, 2022
Dist Ubuntu Esm H88
The Ubuntu security announcement USN-5329-1 outlines an issue with the tar utility, which could lead to system instability in certain scenarios.
tar could be made to crash if it received specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: tar 1.30+dfsg-7ubuntu0.20.04.2 Ubuntu 18.04 LTS: tar 1.29b-2ubuntu0.3 Ubuntu 16.04 ESM: tar 1.28-2.1ubuntu0.2+esm1 Ubuntu 14.04 ESM: tar 1.27.1-1ubuntu0.1+esm2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5329-1

CVE-2021-20193

Severity
critical
Lowest
Low
Medium
High
Critical

March 15, 2022

Package Information

https://launchpad.net/ubuntu/+source/tar/1.30+dfsg-7ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/tar/1.29b-2ubuntu0.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here