#tar clear

CVE-2016-6321: GNU tar path traversal via --strip-components applied after safer_name_suffix

tar CVE-2016-6321: Path-traversal via unvalidated --strip-components

CVE-2022-48303: GNU tar 1.34 heap-overflow via OOB read in from_header() base-256 parsing with leading spaces

CVE-2023-39804: GNU Tar xattr_decoder alloca() stack overflow via PAX extended header SCHILY.xattr value

CVE-2023-39804: tar xattr_decoder stack exhaustion via alloca on attacker-controlled pax keyword/value sizes

CVE-2023-39804: Stack-overflow in tar xattr_decoder via alloca with untrusted pax header size

CVE-2016-6321: GNU tar path traversal via --strip-components

CVE-2016-6321: Path Traversal in tar --strip-components

CVE-2022-48303: tar from_header() base-256 decoder off-by-one heap over-read

CVE-2022-48303: GNU tar heap OOB read in from_header base-256 decoder