oss-sec mailing list archives
Re: Integer overflow in libtar (<= 1.2.19)
From: Naufragium Est <naufragium.est () gmail com>
Date: Thu, 10 Oct 2013 07:04:15 +0200
The announcement of version 1.2.20 can be found at https://lists.feep.net:8080/pipermail/libtar/2013-October/000361.html 2013/10/10 Huzaifa Sidhpurwala <huzaifas () redhat com>
Hi All, Forwarding information from the linux-distros list to oss-sec, since the issue is public now Details: An integer overflow vulnerability was identified in libtar 1.2.19 (and olders) that can possibly be exploited for arbitrary code execution when extracting a specially crafted tar file. A coordinated release date (CRD) of October 9th has been agreed with Chris Frey (libtar developer). This issue is assigned CVE-2013-4397. This issue is fixed in libtar-1.2.20 Reference: Upstream patch: http://repo.or.cz/w/libtar.git/commit/45448e8bae671c2f7e80b860ae0fc0cedf2bdc04 Announcement: This is an announcement about the release on libtar list, but strangely i cant access the list archives. (i am subscribed to the mailing list though) Red Hat bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1014492 -- Huzaifa Sidhpurwala / Red Hat Security Response Team
Current thread:
- Integer overflow in libtar (<= 1.2.19) Huzaifa Sidhpurwala (Oct 09)
- Re: Integer overflow in libtar (<= 1.2.19) Naufragium Est (Oct 09)
- Re: Integer overflow in libtar (<= 1.2.19) Chris Palmer (Oct 09)