Bug 181773 - CVE-2006-0300 GNU tar heap overlfow bug
CVE-2006-0300 GNU tar heap overlfow bug
Status: CLOSED CURRENTRELEASE
Product: Fedora
Classification: Fedora
Component: tar (Show other bugs)
4
All Linux
medium Severity medium
: ---
: ---
Assigned To: Peter Vrabec
Ben Levenson
impact=moderate,source=redhat,reporte...
: Security
: 182404 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2006-02-16 09:17 EST by Josh Bressers
Modified: 2007-11-30 17:11 EST (History)
2 users (show)

See Also:
Fixed In Version: 1.15.1-12.FC4
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-03-03 03:46:00 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2006-02-16 09:17:29 EST
+++ This bug was initially created as a clone of Bug #181772 +++

Jim Meyering discovered and silently fixed a buffer overflow bug in GNU
tar.  It looks exploitable.  There is a public mail message about it here:
http://lists.gnu.org/archive/html/bug-tar/2005-06/msg00029.html

My limited testing has shown this issue to only affect tar versions 1.14
and above.

Upstream has asked we not announce this issue until they release an update.

-- Additional comment from bressers@redhat.com on 2006-02-16 09:11 EST --
Created an attachment (id=124746)
Patch extracted from upstream CVS


-- Additional comment from bressers@redhat.com on 2006-02-16 09:13 EST --
Created an attachment (id=124747)
Testcase generator from Jim
Comment 1 Peter Vrabec 2006-02-22 08:42:38 EST
*** Bug 182404 has been marked as a duplicate of this bug. ***
Comment 2 Mark J. Cox (Product Security) 2006-02-24 04:34:25 EST
remove embargo, fix at will
Comment 3 Peter Vrabec 2006-03-03 03:46:00 EST
fixed in update id #114 tar-1.15.1-12.FC4 and 
devel too
Comment 4 hkoba 2006-04-20 08:26:56 EDT
BTW, when tar-1.15.1-12.FC4 will be released ;-)
I can't find it in master server:

% curl -s http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/i386/|
perl -nle '/href="(tar-[^"]+)/ and print $1'
tar-1.15.1-11.FC4.i386.rpm

Note You need to log in before you can comment on or make changes to this bug.