Bug 31569 - tar new security issue CVE-2022-48303
Summary: tar new security issue CVE-2022-48303
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-02-17 17:19 CET by David Walser
Modified: 2023-03-01 22:16 CET (History)
5 users (show)

See Also:
Source RPM: tar-1.33-2.1.mga8.src.rpm
CVE: CVE-2022-48303
Status comment:


Attachments

Description David Walser 2023-02-17 17:19:58 CET
SUSE has issued an advisory today (February 17):
https://lists.suse.com/pipermail/sle-security-updates/2023-February/013834.html

Mageia 8 is also affected.
David Walser 2023-02-17 17:20:10 CET

Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2023-02-17 20:51:29 CET
Assigning globally because tar does not have an obvious packager; but CC'ing Giuseppe who has done some things to it recently.

Assignee: bugsquad => pkg-bugs
CC: (none) => ghibomgx

Comment 2 David Walser 2023-02-21 17:06:38 CET
openSUSE has issued an advisory for this on February 20:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EMCL5SDDZC2JTGVOT5D2T56IWCRICHJD/
Comment 3 David Walser 2023-02-23 18:05:24 CET
RedHat has issued an advisory for this on February 21:
https://access.redhat.com/errata/RHSA-2023:0842
Comment 4 Nicolas Salguero 2023-03-01 09:31:03 CET
Suggested advisory:
========================

The updated package fixes a security vulnerability:

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters. (CVE-2022-48303)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48303
https://lists.suse.com/pipermail/sle-security-updates/2023-February/013834.html
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EMCL5SDDZC2JTGVOT5D2T56IWCRICHJD/
https://access.redhat.com/errata/RHSA-2023:0842
========================

Updated package in core/updates_testing:
========================
tar-1.33-2.2.mga8

from SRPM:
tar-1.33-2.2.mga8.src.rpm

Whiteboard: MGA8TOO => (none)
Assignee: pkg-bugs => qa-bugs
Source RPM: tar-1.34-4.mga9.src.rpm => tar-1.33-2.1.mga8.src.rpm
CC: (none) => nicolas.salguero
Version: Cauldron => 8
CVE: (none) => CVE-2022-48303
Status: NEW => ASSIGNED

Comment 5 Thomas Andrews 2023-03-01 18:43:45 CET
No installation issues.

Created an archive of photos of a special shape hot air balloon that I have crewed for, named Beagle Maximus. Used the verbose option just to show what was happening.

$ tar -cvf beagle.tar.gz Pictures/Beagle/
Pictures/Beagle/
Pictures/Beagle/beagle maximus.jpg
Pictures/Beagle/Beagle Max circle.jpg
Pictures/Beagle/p4230003.jpg
Pictures/Beagle/Beagle Max.jpg
Pictures/Beagle/421420429_e7527be223_o.jpg
Pictures/Beagle/beagle poster.pdf
Pictures/Beagle/beagle Poster.pdf
Pictures/Beagle/p4230001.jpg
Pictures/Beagle/p4230002.jpg
Pictures/Beagle/1171314392_01b8be2c13_b.jpg
Pictures/Beagle/beagle oval a.jpg
Pictures/Beagle/Beagle Max3.jpg
Pictures/Beagle/Beagle Max2.jpg
Pictures/Beagle/Beagle Max2A.xcf
Pictures/Beagle/beagle maximus2.jpg
Pictures/Beagle/Beagle Max2b.jpg
Pictures/Beagle/Beagle Poster 2.pdf
Pictures/Beagle/p4230004.jpg
Pictures/Beagle/Beagle Max2A.png
Pictures/Beagle/beagle maximus3.jpg
Pictures/Beagle/p4230005.jpg
Pictures/Beagle/Beagle Max4.jpg

Moved the archive to another folder, and extracted it with ARK. All photos looked identical to the originals.

Giving this an OK, and validating. Advisory in comment 4.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs
Whiteboard: (none) => MGA8-64-OK

Dave Hodgins 2023-03-01 19:05:35 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 6 Mageia Robot 2023-03-01 22:16:06 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0079.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.