漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
tar-rs incorrectly ignores PAX size headers if header size is nonzero
Vulnerability Description
tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases where the base header size is nonzero. As part of CVE-2025-62518, the astral-tokio-tar project was changed to correctly honor PAX size headers in the case where it was different from the base header. This is almost the inverse of the astral-tokio-tar issue. Any discrepancy in how tar parsers honor file size can be used to create archives that appear differently when unpacked by different archivers. In this case, the tar-rs (Rust tar) crate is an outlier in checking for the header size - other tar parsers (including e.g. Go archive/tar) unconditionally use the PAX size override. This can affect anything that uses the tar crate to parse archives and expects to have a consistent view with other parsers. This issue has been fixed in version 0.4.45.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Vulnerability Title
tar-rs 安全漏洞
Vulnerability Description
tar-rs是Alex Crichton个人开发者的一个Rust语言的tar归档文件读写库。 tar-rs 0.4.44及之前版本存在安全漏洞,该漏洞源于PAX大小头处理逻辑不一致,可能导致不同解析器解压结果不一致。
CVSS Information
N/A
Vulnerability Type
N/A