{"id":"MGASA-2019-0034","summary":"GNU tar has been updated to fix CVE-2018-20482","details":"GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage\nduring read access, which allows local users to cause a denial of\nservice (infinite read loop in sparse_dump_region in sparse.c) by\nmodifying a file that is supposed to be archived by a different user's\nprocess (e.g., a system backup running as root).\n","modified":"2026-04-16T01:46:28.889429002Z","published":"2019-01-11T21:07:56Z","upstream":["CVE-2018-20482"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0034.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=24117"},{"type":"WEB","url":"https://lists.gnu.org/archive/html/bug-tar/2019-01/msg00000.html"}],"affected":[{"package":{"name":"tar","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/tar?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.31-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0034.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}