Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora Core 2 FEDORA-2005-280 Critical: Sharutils Buffer Overflow

fedora
Calendar Grey April 1, 2005
Dist Fedora Esm H88
The latest sharutils patch for Fedora Core 2 resolves critical buffer overflow vulnerabilities and enhances the management capabilities of the package.
Updated package.

Summary

The sharutils package contains the GNU shar utilities, a set of tools

for encoding and decoding packages of files (in binary or text format)

in a special plain text format called shell archives (shar). This

format can be sent through e-mail (which can be problematic for regular

binary files). The shar utility supports a wide range of capabilities

(compressing, uuencoding, splitting long files for multi-part

mailings, providing checksums), which make it very flexible at

creating shar files. After the files have been sent, the unshar tool

scans mail messages looking for shar files. Unshar automatically

strips off mail headers and introductory text and then unpacks the

shar files.

Install sharutils if you send binary files through e-mail.

- apply patch to fix multiple buffer overflows #152571

- apply patch to fix buffer overflow in handling of -o option,

CAN-2004-1772, #123230

22f58e3841b4ff9de5eef6e5a8d84ef2 SRPMS/sharutils-4.2.1-18.1.FC2.src.rpm

d31b37a68a56df58a08d10605d2b6c8e x86_64/sharutils-4.2.1-18.1.FC2.x86_64.rpm

e8321daa0a4b890aae11dd35306ed344

x86_64/debug/sharutils-debuginfo-4.2.1-18.1.FC2.x86_64.rpm

6f7d0c8bc00709ebe55e56635bbea2d9 i386/sharutils-4.2.1-18.1.FC2.i386.rpm

bc666746782979cb6de3628981e77c5f

i386/debug/sharutils-debuginfo-4.2.1-18.1.FC2.i386.rpm

This update can also be installed with the Update Agent; you can

launch the Update Agent with the 'up2date' command.

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: sharutils
Version: 4.2.1
Release: 18.1.FC2
Summary: The GNU shar utilities for packaging and unpackaging shell

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here