Updated libtar packages fixes security vulnerability
Publication date: 17 Oct 2013Modification date: 17 Oct 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-4397
Description
Two heap-based buffer overflow flaws were found in the way libtar handled certain archives. If a user were tricked into expanding a specially-crafted archive, it could cause the libtar executable or an application using libtar to crash or, potentially, execute arbitrary code (CVE-2013-4397).
References
SRPMS
2/core
- libtar-1.2.11-10.1.mga2
3/core
- libtar-1.2.18-2.1.mga3