Opened 17 years ago

Closed 17 years ago

Last modified 17 years ago

#1926 closed task (fixed)

Security vulnerability in tar

Reported by: Viper Owned by: Matthew Burgess
Priority: normal Milestone:
Component: Book Version: SVN
Severity: normal Keywords:
Cc:

Description

Change History (8)

comment:1 by Matthew Burgess, 17 years ago

Milestone: 6.3
Summary: bug in tarSecurity vulnerability in tar

Thanks. For reference, this is CVE-2006-6097 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6097).

Upstream would appear to favour a different approach than that taken by the patch you linked to. See http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00030.html, where it appears that they're going to remove mangle.c. I'd prefer to wait until upstream publish their recommended patch.

comment:2 by Matthew Burgess, 17 years ago

See http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00042.html for the initial patch for this and http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00043.html for a description of a minor fix that's needed in addition to it. Tar-1.16.1 should be out in about a week that fixes this bug.

comment:3 by robert@…, 17 years ago

Resolution: fixed
Status: newclosed

Tar-1.16.1 is out. Test suite passes on my box (63 passes, 8 skipped), with gzip-1.3.8.

comment:4 by Matthew Burgess, 17 years ago

Resolution: fixed
Status: closedreopened

Reopening - we've not yet upgraded the version of tar in the book.

comment:5 by Matthew Burgess, 17 years ago

Owner: changed from lfs-book@… to Matthew Burgess
Status: reopenednew

comment:6 by Matthew Burgess, 17 years ago

Status: newassigned

comment:7 by Matthew Burgess, 17 years ago

Resolution: fixed
Status: assignedclosed

Fixed in r7902.

comment:8 by Jeremy Huntwork, 17 years ago

Milestone: 6.3

Milestone 6.3 deleted

Note: See TracTickets for help on using tickets.