Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 6: MGASA-2019-0034 Critical: GNU Tar Denial of Service

mageia
Calendar Grey January 11, 2019
Dist Mageia Esm H88
The latest update MGASA-2019-0034 addresses a security flaw in GNU tar, which may cause a denial of service from poor file handling, enhancing system security.
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_...

Summary

Description: GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).

References

- https://bugs.mageia.org/show_bug.cgi?id=24117

- https://lists.gnu.org/archive/html/bug-tar/2019-01/msg00000.html

- https://www.cve.org/CVERecord?id=CVE-2018-20482

Resolution

SRPMS

- 6/core/tar-1.31-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 11 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0034.html
Type: security
CVE: CVE-2018-20482

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here