>> GNU Tar PAX Extended Headers Handling Buffer Overflow Vulnerability
Title : GNU Tar PAX Extended Headers Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-0684 CVE ID : CVE-2006-0300
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-02-22
Technical Description
A vulnerability has been identified in GNU Tar, which could be exploited by attackers to execute arbitrary commands. This flaw is due to a buffer overflow error when handling specially crafted PAX extended headers, which could be exploited by attackers to compromise a vulnerable system by convincing a user to extract a specially crafted archive.