USN-506-1: tar vulnerability
28 August 2007
tar vulnerability
Releases
Packages
- tar -
Details
Dmitry V. Levin discovered that tar did not correctly detect the ".."
file path element when unpacking archives. If a user or an automated
system were tricked into unpacking a specially crafted tar file, arbitrary
files could be overwritten with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.04
Ubuntu 6.10
Ubuntu 6.06
In general, a standard system upgrade is sufficient to effect the
necessary changes.