logo       
Google Custom Search
    AddThis Social Bookmark Button
-->

CVS: cvs.openbsd.org: ports: msg#00001

Subject: CVS: cvs.openbsd.org: ports
CVSROOT:        /cvs
Module name:    ports
Changes by:     brad@xxxxxxxxxxxxxxx    2002/09/30 20:03:52

Modified files:
        archivers/gtar : Makefile 
Added files:
        archivers/gtar/patches: patch-src_extract_c patch-src_misc_c 

Log message:
Fix a directory traversal vulnerability in GNU tar 1.13.25 which allows
attackers to overwrite arbitrary files durring extraction via a ".."
in an extracted filename.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0399




<Prev in Thread] Current Thread [Next in Thread>