CVE-2016-6321: GNU tar path traversal via --strip-components applied after safer_name_suffix
tar CVE-2016-6321: Path-traversal via unvalidated --strip-components
CVE-2022-48303: GNU tar 1.34 heap-overflow via OOB read in from_header() base-256 parsing with leading spaces
CVE-2023-39804: GNU Tar xattr_decoder alloca() stack overflow via PAX extended header SCHILY.xattr value
CVE-2023-39804: tar xattr_decoder stack exhaustion via alloca on attacker-controlled pax keyword/value sizes
CVE-2023-39804: Stack-overflow in tar xattr_decoder via alloca with untrusted pax header size
CVE-2016-6321: GNU tar path traversal via --strip-components
CVE-2016-6321: Path Traversal in tar --strip-components
CVE-2022-48303: tar from_header() base-256 decoder off-by-one heap over-read
CVE-2022-48303: GNU tar heap OOB read in from_header base-256 decoder