Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2806-1

Опубликовано: 30 сент. 2020
Источник: suse-cvrf

Описание

Security update for tar

This update for tar fixes the following issues:

Security issues fixed:

  • CVE-2019-9923: Fixed a denial of service while parsing certain archives with malformed extended headers in pax_decode_header() (bsc#1130496).
  • CVE-2018-20482: Fixed a denial of service when the '--sparse' option mishandles file shrinkage during read access (bsc#1120610).

Список пакетов

Image SLES12-SP4-Azure-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-EC2-HVM-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-GCE-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-OCI-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-Azure
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-Azure-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-EC2-HVM
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-EC2-HVM-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-GCE
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-GCE-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP4-SAP-OCI-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-Basic-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-HPC-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-HPC-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-SAP-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-SAP-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-Azure-Standard-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-EC2-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-EC2-ECS-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-EC2-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-EC2-SAP-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-EC2-SAP-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-GCE-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-GCE-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-GCE-SAP-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-GCE-SAP-On-Demand
tar-1.27.1-15.6.3
Image SLES12-SP5-OCI-BYOS-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
tar-1.27.1-15.6.3
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
tar-1.27.1-15.6.3
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
tar-1.27.1-15.6.3
SUSE Linux Enterprise Server 12 SP5
tar-1.27.1-15.6.3
tar-lang-1.27.1-15.6.3
SUSE Linux Enterprise Server for SAP Applications 12 SP5
tar-1.27.1-15.6.3
tar-lang-1.27.1-15.6.3

Описание

GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-EC2-HVM-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-GCE-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-OCI-BYOS:tar-1.27.1-15.6.3

Ссылки

Описание

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-EC2-HVM-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-GCE-BYOS:tar-1.27.1-15.6.3
Image SLES12-SP4-OCI-BYOS:tar-1.27.1-15.6.3

Ссылки