← Vulnerability feed

Vulnerability record · CVE-2010-0624 · published 15 March 2010

CVE-2010-0624: Gnu cpio memory buffer overflow vulnerability

Gnu · Cpio

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

6.8 CVSS 2.0 Medium EPSS 4.7% · top 8.4% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
64References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.html
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
http://osvdb.org/62950
http://secunia.com/advisories/38869
http://secunia.com/advisories/38988
http://secunia.com/advisories/39008
http://security.gentoo.org/glsa/glsa-201111-11.xml
http://www.agrs.tu-berlin.de/index.php?id=78327 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2010:065
http://www.redhat.com/support/errata/RHSA-2010-0141.html
http://www.redhat.com/support/errata/RHSA-2010-0142.html
http://www.redhat.com/support/errata/RHSA-2010-0144.html
http://www.redhat.com/support/errata/RHSA-2010-0145.html
http://www.securityfocus.com/archive/1/514503/100/0/threaded
http://www.ubuntu.com/usn/USN-2456-1
http://www.vupen.com/english/advisories/2010/0628
http://www.vupen.com/english/advisories/2010/0629
http://www.vupen.com/english/advisories/2010/0639
http://www.vupen.com/english/advisories/2010/0687
http://www.vupen.com/english/advisories/2010/0728
http://www.vupen.com/english/advisories/2010/0729
http://www.vupen.com/english/advisories/2010/1107
https://bugzilla.redhat.com/show_bug.cgi?id=564368 Patch
https://issues.rpath.com/browse/RPL-3219
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10277
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6907
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.html
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html

Track CVE-2010-0624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2541Gnu tar vulnerabilityTar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.EPSS 4.0%7.8CVE-2021-38185Gnu cpio integer overflow vulnerabilityGNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that …EPSS 4.2%7.5CVE-2019-9923Gnu tar null pointer dereference vulnerabilitypax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header…EPSS 3.0%7.5CVE-2016-6321Gnu tar path traversal vulnerabilityDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended p…EPSS 16%7.5CVE-2007-4476Gnu tar memory buffer overflow vulnerabilityBuffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."EPSS 15%7.3CVE-2019-14866Gnu cpio improper input validation vulnerabilityIn all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro…EPSS 0.69%7.2CVE-2010-4226Gnu cpio link following vulnerabilitycpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within…EPSS 2.9%6.8CVE-2007-4131Gnu tar vulnerabilityDirectory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2010-0624), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.