Revision Date: | 2006-03-01 | Version: | 636 |
Title: | RHSA-2006:0232: tar security update (Moderate) |
Description: | The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive.
Jim Meyering discovered a buffer overflow bug in the way GNU tar extracts malformed archives. By tricking a user into extracting a malicious tar archive, it is possible to execute arbitrary code as the user running tar. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2006-0300 to this issue.
Users of tar should upgrade to this updated package, which contains a backported patch to correct this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2006-0300 RHSA-2006:0232 RHSA-2006:0232-01 RHSA-2006:0232-01
|
Platform(s): | Red Hat Enterprise Linux 4
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux must be installed OR Package Information
Red Hat Enterprise Linux 4 is installed
AND tar is earlier than 0:1.14-9.RHEL4
AND tar is signed with Red Hat redhatrelease2 key
|