AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-4397

MEDIUM · CVSS 6.8 EPSS 5.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-10-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-4397
Severity
MEDIUM
CVSS
6.8
EPSS
5.49%

Original NVD Description

Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.