Bug ID 1206547
Summary VUL-0: CVE-2021-33640: libtar: fixes for CVE-2021-33645 and CVE-2021-33646 introduce new use-after-free bugs
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.5
Hardware Other
URL https://smash.suse.de/issue/351269/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee mpluskal@suse.com
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#2143012

Security fixes for CVE-2021-33645 and CVE-2021-33646 introduce new
use-after-free bugs in libtar 1.2.21 in the list() function of
/libtar/libtar.c. The list() function may dereference a pointer t after it has
been freed.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2143012
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-33640
https://www.cve.org/CVERecord?id=CVE-2021-33640
https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2021-33640&packageName=libtar


You are receiving this mail because: