tar is vulnerable to Denial of Service
75
High Risk
When scanning an existing archive before appending replacements, the library advances its read position based on the parsed entry size rounded to a 512-byte block boundary. By crafting a tar header with a valid checksum and a negative base-256 encoded size of -512, an attacker can manipulate the body skip calculation to exactly offset the standard 512-byte header advancement. This results in zero net progress, causing the scanner to repeatedly parse the exact same header indefinitely without ever reaching the append step or terminating, completely pinning the worker process.
You are affected if you are using a version that falls within the vulnerable range.
tar is vulnerable to Denial of Service in versions 0.0.0 - 7.5.17.
Upgrade the tar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant