CVE-2013-4397: Feep Libtar

Medium severity, CVSS 6.8. EPSS: 5.5% chance of exploitation in the next 30 days.

Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.

Affected products

  • Feep Libtar: up to and including 1.2.19; version 1.2.11 only; version 1.2.13 only; version 1.2.14 only; version 1.2.15 only; version 1.2.16 only; …
  • Red Hat Enterprise Linux: version 6.0 only

Published 2013-10-17. Last modified 2026-06-16.