microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy.
History

Mon, 10 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow. microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy.
Title microtar - Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()

Mon, 10 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() microtar - Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()

Thu, 06 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Rxi
Rxi microtar
Vendors & Products Rxi
Rxi microtar

Wed, 05 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.
Title microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published: 2026-08-05T12:26:14.990Z

Updated: 2026-08-10T11:46:37.864Z

Reserved: 2026-08-05T12:23:34.967Z

Link: CVE-2026-71267

cve-icon Vulnrichment

Updated: 2026-08-05T15:54:09.311Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T13:24:50.963

Modified: 2026-08-26T17:13:24.800

Link: CVE-2026-71267

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T12:26:14Z

Links: CVE-2026-71267 - Bugzilla