REDHAT-BUG-280961: Low severity ubuntu tar vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4476 to the following vulnerability:
Bug in the safernamesuffix function in GNU tar may lead to a "crashing stack". It can be used to crash tar while extracting archive containing file with long name containing unsafe prefix.
Affected function is also part of cpio source code.
References:
http://www.novell.com/linux/security/advisories/200718sr.html http://lists.gnu.org/archive/html/bug-cpio/2007-08/msg00002.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-280961?
The severity of REDHAT-BUG-280961 is considered moderate, as it can lead to crashes in the GNU tar application.
How do I fix REDHAT-BUG-280961?
To fix REDHAT-BUG-280961, ensure you are using the latest version of GNU tar or apply the recommended patches provided by your distribution.
What is the impact of REDHAT-BUG-280961?
The impact of REDHAT-BUG-280961 is that it can cause the GNU tar application to crash during the extraction of certain tar files.
What software is affected by REDHAT-BUG-280961?
REDHAT-BUG-280961 affects GNU tar and GNU cpio, potentially leading to application crashes.
Is there a workaround for REDHAT-BUG-280961?
A potential workaround for REDHAT-BUG-280961 is to avoid extracting tar files from untrusted sources until the vulnerability is resolved.