[Bug 1206547] New: VUL-0: CVE-2021-33640: libtar: fixes for CVE-2021-33645 and CVE-2021-33646 introduce new use-after-free bugs
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
http://bugzilla.opensuse.org/show_bug.cgi?id=1206547 Bug ID: 1206547 Summary: VUL-0: CVE-2021-33640: libtar: fixes for CVE-2021-33645 and CVE-2021-33646 introduce new use-after-free bugs Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.5 Hardware: Other URL: https://smash.suse.de/issue/351269/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: mpluskal@suse.com Reporter: cathy.hu@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- rh#2143012 Security fixes for CVE-2021-33645 and CVE-2021-33646 introduce new use-after-free bugs in libtar 1.2.21 in the list() function of /libtar/libtar.c. The list() function may dereference a pointer t after it has been freed. References: https://bugzilla.redhat.com/show_bug.cgi?id=2143012 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-33640 https://www.cve.org/CVERecord?id=CVE-2021-33640 https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2021-33640&packageName=libtar -- You are receiving this mail because: You are on the CC list for the bug.
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
http://bugzilla.opensuse.org/show_bug.cgi?id=1206547
http://bugzilla.opensuse.org/show_bug.cgi?id=1206547#c1
--- Comment #1 from Hu
participants (1)
-
bugzilla_noreply@suse.com