← Vulnerability feed

Vulnerability record · CVE-2006-0300 · published 24 February 2006

CVE-2006-0300: Gnu tar vulnerability

Gnu · Tar

Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.

5.1 CVSS 2.0 Medium EPSS 5.2% · top 7.8%
5.1CVSS 2.0 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
86References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=305214
http://docs.info.apple.com/article.html?artnum=305391
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://lists.gnu.org/archive/html/bug-tar/2006-02/msg00051.html
http://secunia.com/advisories/18973 Vendor Advisory
http://secunia.com/advisories/18976 PatchVendor Advisory
http://secunia.com/advisories/18999 PatchVendor Advisory
http://secunia.com/advisories/19016
http://secunia.com/advisories/19093
http://secunia.com/advisories/19130
http://secunia.com/advisories/19152
http://secunia.com/advisories/19236
http://secunia.com/advisories/20042
http://secunia.com/advisories/24479
http://secunia.com/advisories/24966
http://securityreason.com/securityalert/480
http://securityreason.com/securityalert/543
http://securitytracker.com/id?1015705
http://sunsolve.sun.com/search/document.do?assetkey=1-26-241646-1
http://www.debian.org/security/2006/dsa-987
http://www.gentoo.org/security/en/glsa/glsa-200603-06.xml
http://www.novell.com/linux/security/advisories/2006_05_sr.html
http://www.openpkg.org/security/OpenPKG-SA-2006.006-tar.html
http://www.osvdb.org/23371 Patch
http://www.redhat.com/support/errata/RHSA-2006-0232.html
http://www.securityfocus.com/archive/1/430299/100/0/threaded
http://www.securityfocus.com/bid/16764
http://www.trustix.org/errata/2006/0010 Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-109A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0684
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2007/1470
http://www.vupen.com/english/advisories/2008/2518
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:046 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24855
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5252
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5978
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5993

Track CVE-2006-0300 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2541Gnu tar vulnerabilityTar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.EPSS 4.0%7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2016-6321Gnu tar path traversal vulnerabilityDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…EPSS 16%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%6.8CVE-2010-0624Gnu cpio memory buffer overflow vulnerabilityHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…EPSS 4.7%6.8CVE-2007-4131Gnu tar vulnerabilityDirectory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…EPSS 2.7%6.2CVE-2023-39804Gnu tar vulnerabilityIn GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.EPSS 0.28%5.5CVE-2026-5704Gnu tar unrestricted file upload vulnerabilityA flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2006-0300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.