Bug#917377: tar: CVE-2018-20482

2018-12-28 Thread Salvatore Bonaccorso
Control: tags -1 + fixed-upstream On Wed, Dec 26, 2018 at 09:57:29PM +0100, Salvatore Bonaccorso wrote: > Source: tar > Version: 1.30+dfsg-3 > Severity: important > Tags: security upstream > > Hi, > > The following vulnerability was published for tar. > > CVE-2018-20482[0]: > | GNU Tar through

Bug#917377: tar: CVE-2018-20482

2018-12-26 Thread Salvatore Bonaccorso
Source: tar Version: 1.30+dfsg-3 Severity: important Tags: security upstream Hi, The following vulnerability was published for tar. CVE-2018-20482[0]: | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage | during read access, which allows local users to cause a denial of |