build: unsafe use of cpio
| Package(s): | build |
CVE #(s): | CVE-2010-4226
|
| Created: | March 15, 2011 |
Updated: | April 18, 2011 |
| Description: |
From the openSUSE advisory:
The build script uses cpio to extract untrusted rpm
packages for bootstrapping virtual machines. cpio is not
safe to use for this task, therefore the build script now
uses bsdtar instead |
| Alerts: |
| SUSE |
SUSE-SR:2011:005 |
hplip, perl, subversion, t1lib, bind, tomcat5, tomcat6, avahi, gimp, aaa_base, build, libtiff, krb5, nbd, clamav, aaa_base, flash-player, pango, openssl, subversion, postgresql, logwatch, libxml2, quagga, fuse, util-linux |
2011-04-01 |
| openSUSE |
openSUSE-SU-2011:0174-1 |
build |
2011-03-15 |
|