Oval Definition:oval:com.redhat.rhsa:def:20060232
Revision Date:2006-03-01Version:636
Title:RHSA-2006:0232: tar security update (Moderate)
Description:The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive.

Jim Meyering discovered a buffer overflow bug in the way GNU tar extracts malformed archives. By tricking a user into extracting a malicious tar archive, it is possible to execute arbitrary code as the user running tar. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2006-0300 to this issue.

Users of tar should upgrade to this updated package, which contains a backported patch to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2006-0300
RHSA-2006:0232
RHSA-2006:0232-01
RHSA-2006:0232-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND tar is earlier than 0:1.14-9.RHEL4
  • AND tar is signed with Red Hat redhatrelease2 key
  • BACK