RHSA-2010:0505: Moderate: perl-Archive-Tar security update
The Archive::Tar module provides a mechanism for Perl scripts to manipulatetar archive files.Multiple directory traversal flaws were discovered in the Archive::Tarmodule. A specially-crafted tar file could cause a Perl script, using theArchive::Tar module to extract the archive, to overwrite an arbitrary filewritable by the user running the script. (CVE-2007-4829)This package upgrades the Archive::Tar module to version 1.3901. Refer tothe Archive::Tar module's changes file, linked to in the References, for afull list of changes.Users of perl-Archive-Tar are advised to upgrade to this updated package,which corrects these issues. All applications using the Archive::Tar modulemust be restarted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0505?
The severity of RHSA-2010:0505 is classified as moderate.
How do I fix RHSA-2010:0505?
To fix RHSA-2010:0505, update the Archive::Tar module to the latest version available.
What are the implications of RHSA-2010:0505?
The implications of RHSA-2010:0505 include potential directory traversal vulnerabilities when extracting specially-crafted tar files.
Which versions are affected by RHSA-2010:0505?
RHSA-2010:0505 affects older versions of the Archive::Tar module, prior to the security update.
What is the primary issue addressed in RHSA-2010:0505?
The primary issue addressed in RHSA-2010:0505 is multiple directory traversal flaws within the Archive::Tar module.