Sploitus

CVE-2022-48303

No indexed exploits for CVE-2022-48303 yet

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

Gnu Tar
≤ 1.34
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
4.5% (91th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2023-01-30
CVE-2022-48303 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-48303 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-48303 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.