CLSA-2023-1677784249

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2023-1677784249.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2023-1677784249
Upstream
Published
2023-03-02T19:10:49Z
Modified
2026-06-04T10:04:07.028543295Z
Summary
Fix CVE(s): CVE-2022-48303, CVE-2021-20193
Details
  • SECURITY UPDATE: memory leak in read_header
    • debian/patches/CVE-2021-20193.patch: Don't return directly from the loop. Instead set the status and break. Return the status.
    • CVE-2021-20193.patch
  • SECURITY UPDATE: a heap buffer overflow
    • debian/patches/CVE-2022-48303.patch: Check for the end of field after leading byte (0x80 or 0xff) of base-256 encoded header value.
    • CVE-2022-48303.patch
  • improve debian/rules to build the project by root
References

Affected packages

TuxCare:Ubuntu:16.04 / tar

Package

Name
tar
Purl
pkg:deb/tuxcare/tar?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.28-2.1ubuntu0.2+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2023-1677784249.json"

TuxCare:Ubuntu:16.04 / tar-scripts

Package

Name
tar-scripts
Purl
pkg:deb/tuxcare/tar-scripts?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.28-2.1ubuntu0.2+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2023-1677784249.json"