+++ This bug was initially created as a clone of Bug #152571 +++
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to
execute arbitrary code via a long -o command line argument.
To test this:
shar -o `perl -e 'print "A"x2000'`
A patch is located here:
it's fixed in sharutils-4.2.1-18.1.FC2