libtar 1.2.16-1+deb7u2 source package in Debian

Changelog

libtar (1.2.16-1+deb7u2) wheezy-security; urgency=low


  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
    pathname prefix containing ".." components (Closes: #731860). This is
    done in th_get_pathname() (as well as to symlink targets when
    extracting symlinks), not merely when extracting files, which means
    applications calling that function will not see the stored
    filename. There is no way to disable this behaviour, but it can be
    expected that one will be provided when the issue is solved upstream.
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
    result from oct_to_int() to unsigned int. This is the right fix for
    bug #725938 on 64-bit systems, where a specially crafted tar file
    would not cause an integer overflow, but a memory allocation of almost
    16 exbibytes, which would certainly fail outright without harm.

 -- Magnus Holmgren <email address hidden>  Sun, 16 Feb 2014 19:12:18 +0100

Upload details

Uploaded by:
Magnus Holmgren
Uploaded to:
Wheezy
Original maintainer:
Magnus Holmgren
Architectures:
any
Section:
libs
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Wheezy release main libs

Builds

Downloads

File Size SHA-256 Checksum
libtar_1.2.16-1+deb7u2.dsc 1.2 KiB b63c5e990dccc47c6e969849cbe151510516459e3ba975135c3f6ed4f6816ace
libtar_1.2.16.orig.tar.gz 60.6 KiB e5ae2daa0f984664dcde2229346d252251c873a76abbfedd1ee346354e0ec3f7
libtar_1.2.16-1+deb7u2.debian.tar.gz 7.5 KiB 1cfa13f3a03db741ad8caf21cd28ba171cab26f0edf7f1d3227d0661ab47d572

No changes file available.

Binary packages built by this source