CVE-2010-0624
EPSS 1.5%
Description
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
How to fix CVE-2010-0624
To remediate CVE-2010-0624, upgrade the affected package to a fixed version below.
- Debian/cpio—upgrade to 2.11-1 or later
- Debian/tar—upgrade to 1.23-1 or later
Is CVE-2010-0624 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.11-1
- from 0, < 1.23-1