MGASA-2019-0034

Source
https://advisories.mageia.org/MGASA-2019-0034.html
Import Source
https://advisories.mageia.org/MGASA-2019-0034.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0034
Related
Published
2019-01-11T21:07:56Z
Modified
2019-01-11T20:40:46Z
Summary
GNU tar has been updated to fix CVE-2018-20482
Details

GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparsedumpregion in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).

References
Credits

Affected packages

Mageia:6 / tar

Package

Name
tar
Purl
pkg:rpm/mageia/tar?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.31-1.mga6

Ecosystem specific

{
    "section": "core"
}