tar, cpio: arbitrary code execution
| Package(s): | tar cpio |
CVE #(s): | CVE-2010-0624
|
| Created: | March 16, 2010 |
Updated: | December 1, 2013 |
| Description: |
From the Red Hat advisory:
A heap-based buffer overflow flaw was found in the way tar and expand
archive
files. If a user were tricked into expanding a specially-crafted archive,
it could cause the executable to crash or execute arbitrary code with
the privileges of the user running it. |
| Alerts: |
| Ubuntu |
USN-2456-1 |
cpio |
2015-01-08 |
| Gentoo |
201311-21 |
cpio |
2013-11-28 |
| Gentoo |
201111-11 |
tar |
2011-11-20 |
| rPath |
rPSA-2010-0070-1 |
cpio tar |
2010-10-27 |
| SuSE |
SUSE-SR:2010:011 |
dovecot12, cacti, java-1_6_0-openjdk, irssi, tar, fuse, apache2, libmysqlclient-devel, cpio, moodle, libmikmod, libicecore, evolution-data-server, libpng/libpng-devel, libesmtp |
2010-05-10 |
| Pardus |
2010-42 |
tar-1.21-18-4 cpio-2.9-9-5 cpio-2.9-9-4 tar-1.20-17-4 |
2010-03-29 |
| Fedora |
FEDORA-2010-4306 |
tar |
2010-03-12 |
| Fedora |
FEDORA-2010-4302 |
cpio |
2010-03-12 |
| Mandriva |
MDVSA-2010:065 |
cpio |
2010-03-23 |
| CentOS |
CESA-2010:0143 |
cpio |
2010-03-17 |
| CentOS |
CESA-2010:0142 |
tar |
2010-03-17 |
| CentOS |
CESA-2010:0145 |
cpio |
2010-03-17 |
| Fedora |
FEDORA-2010-4321 |
cpio |
2010-03-12 |
| CentOS |
CESA-2010:0141 |
tar |
2010-03-16 |
| CentOS |
CESA-2010:0144 |
cpio |
2010-03-16 |
| Fedora |
FEDORA-2010-4309 |
tar |
2010-03-12 |
| Red Hat |
RHSA-2010:0145-01 |
cpio |
2010-03-15 |
| Red Hat |
RHSA-2010:0144-01 |
cpio |
2010-03-15 |
| Red Hat |
RHSA-2010:0143-01 |
cpio |
2010-03-15 |
| Red Hat |
RHSA-2010:0142-01 |
tar |
2010-03-15 |
| Red Hat |
RHSA-2010:0141-01 |
tar |
2010-03-15 |
|