Mageia alert MGASA-2013-0309 (libtar)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2013-0309: Updated libtar packages fixes security vulnerability | |
| Date: | Thu, 17 Oct 2013 21:37:47 +0200 | |
| Message-ID: | <20131017193747.BAACB48A53@valstar.mageia.org> |
MGASA-2013-0309 - Updated libtar packages fixes security vulnerability Publication date: 17 Oct 2013 URL: http://advisories.mageia.org/MGASA-2013-0309.html Type: security Affected Mageia releases: 2, 3 CVE: CVE-2013-4397 Description: Two heap-based buffer overflow flaws were found in the way libtar handled certain archives. If a user were tricked into expanding a specially-crafted archive, it could cause the libtar executable or an application using libtar to crash or, potentially, execute arbitrary code (CVE-2013-4397). References: - https://bugs.mageia.org/show_bug.cgi?id=11424 - https://rhn.redhat.com/errata/RHSA-2013-1418.html - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4397 SRPMS: - 3/core/libtar-1.2.18-2.1.mga3 - 2/core/libtar-1.2.11-10.1.mga2