Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rxi
Rxi microtar |
|
| Vendors & Products |
Rxi
Rxi microtar |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a crafted TAR archive with non-null-terminated name or linkname fields. The function uses strcpy() to copy 100-byte ustar format fields that lack null terminators, causing writes of up to 355 bytes into a 100-byte destination buffer when mtar_open(), mtar_find(), or mtar_read_header() process attacker-supplied TAR archives. | |
| Title | microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header() | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:16:32.277Z
Reserved: 2026-05-01T18:22:45.640Z
Link: CVE-2026-43623
Updated: 2026-06-02T15:38:45.078Z
Status : Deferred
Published: 2026-06-01T19:16:46.723
Modified: 2026-06-02T14:43:49.920
Link: CVE-2026-43623
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:52:56Z