MGASA-2022-0488

Source
https://advisories.mageia.org/MGASA-2022-0488.html
Import Source
https://advisories.mageia.org/MGASA-2022-0488.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0488
Upstream
  • CVE-2021-33640
Published
2022-12-30T22:39:00Z
Modified
2026-04-16T04:43:54Z
Summary
Updated libtar packages fix security vulnerability
Details

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free). (CVE-2021-33640)

References
Credits

Affected packages

Mageia:8 / libtar

Package

Name
libtar
Purl
pkg:rpm/mageia/libtar?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.20-9.2.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2022-0488.json"