Oval Definition:oval:com.redhat.rhsa:def:20131418
Revision Date:2013-10-10Version:637
Title:RHSA-2013:1418: libtar security update (Moderate)
Description:The libtar package contains a C library for manipulating tar archives. The library supports both the strict POSIX tar format and many of the commonly used GNU extensions.

  • Two heap-based buffer overflow flaws were found in the way libtar handled certain archives. If a user were tricked into expanding a specially-crafted archive, it could cause the libtar executable or an application using libtar to crash or, potentially, execute arbitrary code. (CVE-2013-4397)

    Note: This issue only affected 32-bit builds of libtar.

    Red Hat would like to thank Timo Warns for reporting this issue.

    All libtar users are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4397
    CVE-2013-4397
    RHSA-2013:1418
    RHSA-2013:1418-01
    RHSA-2013:1418-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libtar is earlier than 0:1.2.11-17.el6_4.1
  • AND libtar is signed with Red Hat redhatrelease2 key
  • libtar-devel is earlier than 0:1.2.11-17.el6_4.1
  • AND libtar-devel is signed with Red Hat redhatrelease2 key
  • BACK