CVE-2023-39804: GNU Tar
Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
Affected products
- GNU Tar: before 1.35 (fixed in 1.35)
Published 2024-03-27. Last modified 2026-06-17.