Lucene search

K
centosCentOS ProjectCESA-2010:0142
HistoryMar 17, 2010 - 3:26 p.m.

tar security update

2010-03-1715:26:37
CentOS Project
lists.centos.org
56

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.013

Percentile

85.9%

CentOS Errata and Security Advisory CESA-2010:0142

The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive.

A heap-based buffer overflow flaw was found in the way tar expanded archive
files. If a user were tricked into expanding a specially-crafted archive,
it could cause the tar executable to crash or execute arbitrary code with
the privileges of the user running tar. (CVE-2010-0624)

Red Hat would like to thank Jakob Lell for responsibly reporting this
issue.

Users of tar are advised to upgrade to this updated package, which contains
a backported patch to correct this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2010-March/078726.html
https://lists.centos.org/pipermail/centos-announce/2010-March/078727.html

Affected packages:
tar

Upstream details at:
https://access.redhat.com/errata/RHSA-2010:0142

OSVersionArchitecturePackageVersionFilename
CentOS3i386tar<ย 1.13.25-16.RHEL3tar-1.13.25-16.RHEL3.i386.rpm
CentOS3i386tar<ย 1.13.25-16.RHEL3tar-1.13.25-16.RHEL3.i386.rpm
CentOS3x86_64tar<ย 1.13.25-16.RHEL3tar-1.13.25-16.RHEL3.x86_64.rpm
CentOS3x86_64tar<ย 1.13.25-16.RHEL3tar-1.13.25-16.RHEL3.x86_64.rpm

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.013

Percentile

85.9%