Advisories ยป MGASA-2013-0309

Updated libtar packages fixes security vulnerability

Publication date: 17 Oct 2013
Modification date: 17 Oct 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-4397

Description

Two heap-based buffer overflow flaws were found in the way libtar handled
certain archives. If a user were tricked into expanding a specially-crafted
archive, it could cause the libtar executable or an application using
libtar to crash or, potentially, execute arbitrary code (CVE-2013-4397).
                

References

SRPMS

3/core

2/core