VYPR
Medium severity5.5NVD Advisory· Published Jan 30, 2023· Updated Jun 17, 2026

CVE-2022-48303

CVE-2022-48303

Description

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.