|
|
Log in / Subscribe / Register

tar, cpio: arbitrary code execution

Package(s):tar cpio CVE #(s):CVE-2010-0624
Created:March 16, 2010 Updated:December 1, 2013
Description: From the Red Hat advisory:

A heap-based buffer overflow flaw was found in the way tar and expand archive files. If a user were tricked into expanding a specially-crafted archive, it could cause the executable to crash or execute arbitrary code with the privileges of the user running it.

Alerts:
Ubuntu USN-2456-1 cpio 2015-01-08
Gentoo 201311-21 cpio 2013-11-28
Gentoo 201111-11 tar 2011-11-20
rPath rPSA-2010-0070-1 cpio tar 2010-10-27
SuSE SUSE-SR:2010:011 dovecot12, cacti, java-1_6_0-openjdk, irssi, tar, fuse, apache2, libmysqlclient-devel, cpio, moodle, libmikmod, libicecore, evolution-data-server, libpng/libpng-devel, libesmtp 2010-05-10
Pardus 2010-42 tar-1.21-18-4 cpio-2.9-9-5 cpio-2.9-9-4 tar-1.20-17-4 2010-03-29
Fedora FEDORA-2010-4306 tar 2010-03-12
Fedora FEDORA-2010-4302 cpio 2010-03-12
Mandriva MDVSA-2010:065 cpio 2010-03-23
CentOS CESA-2010:0143 cpio 2010-03-17
CentOS CESA-2010:0142 tar 2010-03-17
CentOS CESA-2010:0145 cpio 2010-03-17
Fedora FEDORA-2010-4321 cpio 2010-03-12
CentOS CESA-2010:0141 tar 2010-03-16
CentOS CESA-2010:0144 cpio 2010-03-16
Fedora FEDORA-2010-4309 tar 2010-03-12
Red Hat RHSA-2010:0145-01 cpio 2010-03-15
Red Hat RHSA-2010:0144-01 cpio 2010-03-15
Red Hat RHSA-2010:0143-01 cpio 2010-03-15
Red Hat RHSA-2010:0142-01 tar 2010-03-15
Red Hat RHSA-2010:0141-01 tar 2010-03-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds