klieber Bodhisattva
Joined: 17 Apr 2002 Posts: 3657 Location: San Francisco, CA
|
Posted: Tue Oct 01, 2002 1:52 pm Post subject: [gentoo-announce] GLSA: tar |
|
|
Daniel Ahlberg wrote: | - - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT
- - --------------------------------------------------------------------
PACKAGE :tar
SUMMARY :directory-traversal vulnerability
DATE :2002-10-01 12:30 UTC
- - --------------------------------------------------------------------
OVERVIEW
The tar utility contain vulnerabilities which can allow arbitrary files to be overwritten during archive extraction.
DETAIL
During testing by Redhat of the fix to GNU tar from the advisory below, it was discovered that GNU tar 1.13.25 was still vulnerable to a modified version of the same problem.
Read the full original advisory at
http://marc.theaimsgroup.com/?l=bugtraq&m=99496364810666&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running sys-apps/tar-1.13.25-r2 and earlier update their systems as follows:
emerge rsync
emerge tar
emerge clean
- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - -------------------------------------------------------------------- |
Mailing List Archive: http://lists.gentoo.org/pipermail/gentoo-announce/2002-October/000211.html
--kurt _________________ The problem with political jokes is that they get elected |
|