Back

HIGH

tar: null-pointer dereference in pax_decode_header in sparse.c

Published Mar 22, 2019

Description

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

Affected products

Remediation

Red Hat statement

This issue is classified with a low severity primarily because untrusted tar files are not typically extracted with the root user, limiting the impact of this issue. Additionally, this NULL pointer dereference is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with tar. Furthermore, tar does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 22, 2019
Updated Aug 6, 2025
Reserved Mar 22, 2019
CISA Vulnrichment
Updated Aug 6, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 2, 2019