VDB
CVE-2025-3573
CVE-2025-3573
PUBLISHED
CVSS 4.300000190734863 MEDIUM
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
EPSS 0.34% · 57.1th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS Score
0.34%
57.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go standard library | archive/tar | 1.25.0, 0 |
Exploit Intelligence
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- validation de l'exploitabilité d'une CVE (github-poc)
- Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027. (github-poc)
- Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027. (github-poc)
…and 377 more exploits
Timeline
- Jan 20, 1970 Fix PR Merged
- Jun 28, 2021 PoC Published
- Oct 5, 2023 PoC Published
- Apr 15, 2025 CVE Published
- Apr 15, 2025 EPSS Score
- Apr 27, 2025 EPSS Score
- Apr 28, 2025 PoC Published
- May 10, 2025 EPSS Score
- May 22, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
- Jun 16, 2025 EPSS Score
- Jun 18, 2025 Coalition ESS Score
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36626 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36633 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36630 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36631 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36629 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36632 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36627 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36628 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36625 advisory
- https://go.dev/cl/709861 url
- https://go.dev/issue/75677 url
- https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI url
- https://pkg.go.dev/vuln/GO-2025-4014 url
- http://www.openwall.com/lists/oss-security/2025/10/08/1 url