Debian LTS: DLA-4033-1: libtar Security Advisory Updates
Summary
CVE-2021-33643
out-of-bounds read in gnu_longlink()
CVE-2021-33644
out-of-bounds read in gnu_longname()
CVE-2021-33645
memory leak in th_read()
CVE-2021-33646
memory leak in th_read()
For Debian 11 bullseye, these problems have been fixed in version
1.2.20-8+deb12u1~deb11u1.
We recommend that you upgrade your libtar packages.
For the detailed security status of libtar please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libtar
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS