GLSA: tar

From: Daniel Ahlberg (alizat_private)
Date: Tue Oct 01 2002 - 05:37:48 PDT

  • Next message: Marc Bevand: "ASA-0000: GV Execution of Arbitrary Shell Commands"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT
    - - --------------------------------------------------------------------
    
    PACKAGE        :tar
    SUMMARY        :directory-traversal vulnerability
    DATE           :2002-10-01 12:30 UTC
    
    - - --------------------------------------------------------------------
    
    OVERVIEW
    
    The tar utility contain vulnerabilities which can allow
    arbitrary files to be overwritten during archive extraction.
    
    DETAIL
    
    During testing by Redhat of the fix to GNU tar from the advisory below, 
    it was discovered that GNU tar 1.13.25 was still vulnerable to a 
    modified version of the same problem.
    
    Read the full original advisory at
    http://marc.theaimsgroup.com/?l=bugtraq&m=99496364810666&w=2
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    sys-apps/tar-1.13.25-r2 and earlier update their systems
    as follows:
    
    emerge rsync
    emerge tar
    emerge clean
    
    - - --------------------------------------------------------------------
    alizat_private - GnuPG key is available at www.gentoo.org/~aliz
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)
    
    iD8DBQE9mZcbfT7nyhUpoZMRAgTqAJ9TIgnwCf6vABCsQp7fZ/WpHUoCNACdGzJH
    2yxb1ASJvjfl5ToRzzfJ8oM=
    =7aPP
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Tue Oct 01 2002 - 08:01:49 PDT