Lucene search

K
suseSuseSUSE-SU-2016:1939-1
HistoryAug 02, 2016 - 5:08 p.m.

Security update for bsdtar (important)

2016-08-0217:08:50
lists.opensuse.org
15

0.059 Low

EPSS

Percentile

93.5%

bsdtar was updated to fix seven security issues.

These security issues were fixed:

  • CVE-2015-8929: Memory leak in tar parser (bsc#985669).
  • CVE-2016-4809: Memory allocate error with symbolic links in cpio
    archives (bsc#984990).
  • CVE-2015-8920: Stack out of bounds read in ar parser (bsc#985675).
  • CVE-2015-8921: Global out of bounds read in mtree parser (bsc#985682).
  • CVE-2015-8924: Heap buffer read overflow in tar (bsc#985609).
  • CVE-2015-8918: Overlapping memcpy in CAB parser (bsc#985698).
  • CVE-2015-2304: Reject absolute paths in input mode of bsdcpio exactly
    when ‘…’ is rejected (bsc#920870).