Home page logo

oss-sec logo oss-sec mailing list archives

Integer overflow in libtar (<= 1.2.19)
From: Huzaifa Sidhpurwala <huzaifas () redhat com>
Date: Thu, 10 Oct 2013 10:06:05 +0530

Hi All,

Forwarding information from the linux-distros list to oss-sec, since
the issue is public now


An integer overflow vulnerability was identified in libtar 1.2.19 (and
olders) that can possibly be exploited for arbitrary code execution when
extracting a specially crafted tar file.

A coordinated release date (CRD) of October 9th has been agreed with
Chris Frey (libtar developer).

This issue is assigned CVE-2013-4397.
This issue is fixed in libtar-1.2.20


Upstream patch:

Announcement: This is an announcement about the release on
libtar list, but strangely i cant access the list archives.
(i am subscribed to the mailing list though)

Red Hat bugzilla:

Huzaifa Sidhpurwala / Red Hat Security Response Team

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]