CVE-2007-4476 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 14.9% (pctl 97)
Patch early
A public exploit exists.
Description
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 14.9% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-09-05 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| gnu | tar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GNU TAR 1.15.91 / CPIO 2.5.90 - 'safer_name_suffix' Remote Denial of Service | 2007-11-14 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=196978
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://secunia.com/advisories/26674
- http://secunia.com/advisories/26987
- http://secunia.com/advisories/27331
- http://secunia.com/advisories/27453
- http://secunia.com/advisories/27514
- http://secunia.com/advisories/27681
- http://secunia.com/advisories/27857
- http://secunia.com/advisories/28255
- http://secunia.com/advisories/29968
- http://secunia.com/advisories/32051
- http://secunia.com/advisories/33567
- http://secunia.com/advisories/39008
- http://security.gentoo.org/glsa/glsa-200711-18.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1
- http://www.debian.org/security/2007/dsa-1438
- http://www.debian.org/security/2008/dsa-1566
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:197
→ the Explorer · watch your stack · NVD