First published: Fri Feb 12 2010(Updated: )
A heap-based buffer overflow flaw was found in the way tar and cpio archive manipulation tools expanded archives with certain character in the archive name. If a local user was tricked into expanding a specially-crafted archive, it could cause the tar, cpio executables to crash or, potentially, to execute arbitrary code with the privileges of the user running the utility. Link to advisory: [1] <a href="http://www.agrs.tu-berlin.de/index.php?id=78327">http://www.agrs.tu-berlin.de/index.php?id=78327</a> Acknowledgements: Red Hat would like to thank Jakob Lell for responsibly reporting this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU tar | =1.14.1 | |
GNU tar | =1.13.17 | |
GNU cpio | =2.9 | |
GNU tar | =1.13.25 | |
GNU tar | <=1.22 | |
GNU cpio | =2.5.90 | |
GNU tar | =1.13 | |
GNU cpio | =1.1 | |
GNU tar | =1.13.5 | |
GNU cpio | =1.3 | |
GNU tar | =1.18 | |
GNU tar | =1.13.18 | |
GNU tar | =1.19 | |
GNU tar | =1.20 | |
GNU cpio | =2.7 | |
GNU tar | =1.17 | |
GNU cpio | =1.2 | |
GNU tar | =1.15.90 | |
GNU tar | =1.16 | |
GNU cpio | =2.6 | |
GNU cpio | <=2.10 | |
GNU tar | =1.14 | |
GNU tar | =1.13.14 | |
GNU tar | =1.15.91 | |
GNU tar | =1.13.19 | |
GNU tar | =1.14.90 | |
GNU cpio | =2.5 | |
GNU tar | =1.15 | |
GNU cpio | =1.0 | |
GNU tar | =1.13.11 | |
GNU tar | =1.15.1 | |
GNU cpio | =2.8 | |
GNU tar | =1.13.16 | |
GNU cpio | =2.4-2 | |
GNU tar | =1.21 | |
GNU tar | =1.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.