Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

FLEA-2007-0049-1 tar

From: Foresight Linux Essential Announcement Service <foresight-security-noreply(at)foresightlinux.org>
Date: Mon Aug 27 2007 - 08:44:34 EDT


-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Foresight Linux Essential Advisory: 2007-0049-1 Published: 2007-08-27

Rating: Severe

Updated Versions:

    tar=/conary.rpath.com@rpl:devel//1/1.15.1-7.2-1     group-dist=/foresight.rpath.org@fl:1-devel//1/1.3.2-0.10-1

References:

    
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1267
    
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0399
    
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131
    https://issues.rpath.com/browse/RPL-1631

Description:

    Previous versions of the tar package are vulnerable to an attack in     which unpacking an intentionally-malformed tar archive can overwrite     arbitrary files to which the user running tar has write access. If the     attacking user knows the name of a vulnerable binary file and overwrites     it, this allows the attacker to place arbitrary code on the system which     is likely to be run. If root is running tar, this includes any file on     the system, which would elevate this to an indirect non-deterministic     remote root unauthorized access vulnerability.

  • ---
Do you need help?X

Copyright 2007 Foresight Linux Project
This file is distributed under the terms of the MIT License. A copy is available at http://www.foresightlinux.org/permanent/mit-license.html
-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFG0scsWu/kq4lN9jkRAg1QAKCLUKCja3x6mYE2UPg4gx/UhV7HKACfVam/ pqYxERJoh5zq9L/zVehiNw4=
=IbBY
-----END PGP SIGNATURE-----
Received on Mon Aug 27 16:15:30 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:39 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library