Opened 20 years ago

Closed 20 years ago

Last modified 19 years ago

#1926 closed task (fixed)

Security vulnerability in tar

Reported by: Viper Owned by: Matthew Burgess
Priority: normal Milestone:
Component: Book Version: SVN
Severity: normal Keywords:
Cc:

Description

Change History (8)

comment:1 by Matthew Burgess, 20 years ago

Milestone: → 6.3
Summary: bug in tar → Security vulnerability in tar

Thanks. For reference, this is CVE-2006-6097 (​http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6097).

Upstream would appear to favour a different approach than that taken by the patch you linked to. See ​http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00030.html, where it appears that they're going to remove mangle.c. I'd prefer to wait until upstream publish their recommended patch.

comment:2 by Matthew Burgess, 20 years ago

See ​http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00042.html for the initial patch for this and ​http://lists.gnu.org/archive/html/bug-tar/2006-11/msg00043.html for a description of a minor fix that's needed in addition to it. Tar-1.16.1 should be out in about a week that fixes this bug.

comment:3 by robert@…, 20 years ago

Resolution: → fixed
Status: new → closed

Tar-1.16.1 is out. Test suite passes on my box (63 passes, 8 skipped), with gzip-1.3.8.

comment:4 by Matthew Burgess, 20 years ago

Resolution: fixed
Status: closed → reopened

Reopening - we've not yet upgraded the version of tar in the book.

comment:5 by Matthew Burgess, 20 years ago

Owner: changed from lfs-book@… to Matthew Burgess
Status: reopened → new

comment:6 by Matthew Burgess, 20 years ago

Status: new → assigned

comment:7 by Matthew Burgess, 20 years ago

Resolution: → fixed
Status: assigned → closed

Fixed in r7902.

comment:8 by Jeremy Huntwork, 19 years ago

Milestone: 6.3

Milestone 6.3 deleted

Note: See TracTickets for help on using tickets.