|
|||||||||||
|
FLEA-2007-0049-1 tar
From: Foresight Linux Essential Announcement Service <foresight-security-noreply(at)foresightlinux.org>
Date: Mon Aug 27 2007 - 08:44:34 EDT
Foresight Linux Essential Advisory: 2007-0049-1 Published: 2007-08-27 Rating: Severe Updated Versions: tar=/conary.rpath.com@rpl:devel//1/1.15.1-7.2-1 group-dist=/foresight.rpath.org@fl:1-devel//1/1.3.2-0.10-1 References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1267
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0399
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131
https://issues.rpath.com/browse/RPL-1631Description: Previous versions of the tar package are vulnerable to an attack in which unpacking an intentionally-malformed tar archive can overwrite arbitrary files to which the user running tar has write access. If the attacking user knows the name of a vulnerable binary file and overwrites it, this allows the attacker to place arbitrary code on the system which is likely to be run. If root is running tar, this includes any file on the system, which would elevate this to an indirect non-deterministic remote root unauthorized access vulnerability.
Copyright 2007 Foresight Linux Project
iD8DBQFG0scsWu/kq4lN9jkRAg1QAKCLUKCja3x6mYE2UPg4gx/UhV7HKACfVam/
pqYxERJoh5zq9L/zVehiNw4=
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:39 EDT |
||||||||||
|
|||||||||||