tar-1.15.1-23.0.1.AXS3.2

エラータID: AXSA:2010-148:01

Release date: 
Tuesday, March 16, 2010 - 13:55
Subject: 
tar-1.15.1-23.0.1.AXS3.2
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive. Tar can also be used to add supplemental files to an archive and to update or list files in the archive. Tar includes multivolume support, automatic archive compression/decompression, the ability to perform remote archives, and the ability to perform incremental and full backups.
If you want to use tar for remote backups, you also need to install the rmt package.
Security issues fixed with this release:
CVE-2007-4476
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a 'crashing stack.'
CVE-2010-0624
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tar-1.15.1-23.0.1.AXS3.2.src.rpm
    MD5: 4f32bb08da3112a0057de7de013ee95a
    SHA-256: 932628d3863d66c6109d9bda808bbe51504c32d87373b2f002b65dfa46377fb1
    Size: 2.16 MB

Asianux Server 3 for x86
  1. tar-1.15.1-23.0.1.AXS3.2.i386.rpm
    MD5: 9e96638551f25192ad338df000e3475d
    SHA-256: 7f2f52a972db9598a083069c3fdc3cd135d6026fe488d3c53c260965eae711cf
    Size: 746.79 kB

Asianux Server 3 for x86_64
  1. tar-1.15.1-23.0.1.AXS3.2.x86_64.rpm
    MD5: 6fb4a82451f88810f83bdf49d39aea4d
    SHA-256: 44eb2cafc7808d4e7f2c348609888c2704164485af76233ad732be1fb01c7fb9
    Size: 746.51 kB