Description: | Description:
The remote host is missing an update to tar announced via advisory FEDORA-2007-1890.
The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive. Tar can also be used to add supplemental files to an archive and to update or list files in the archive. Tar includes multivolume support, automatic archive compression/decompression, the ability to perform remote archives, and the ability to perform incremental and full backups.
If you want to use tar for remote backups, you also need to install the rmt package.
ChangeLog:
* Tue Aug 28 2007 Radek Brich 2:1.15.1-27 - fixed CVE-2007-4131 tar directory traversal vulnerability (#253684) References:
[ 1 ] Bug #253684 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=253684 [ 2 ] CVE-2007-4131 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131 Updated packages:
bd8087f28ac3543985fdd20925576c6bd30a6052 tar-debuginfo-1.15.1-27.fc7.ppc64.rpm 570600876a6aea95d037c08b0535dca556ef8e54 tar-1.15.1-27.fc7.ppc64.rpm b1daf539622c49c6eac21e61fcf46d8944ffa7d9 tar-1.15.1-27.fc7.i386.rpm 120984df639499b8510406e5ad8290d59fd27a68 tar-debuginfo-1.15.1-27.fc7.i386.rpm f090162ea9d38447f52ef1e040de8cc73d43425c tar-1.15.1-27.fc7.x86_64.rpm a8d12080387b64d6748bbd2173de076faf086c78 tar-debuginfo-1.15.1-27.fc7.x86_64.rpm 8a8443f8c2914b8be18a1c2e03213ae3cf698146 tar-debuginfo-1.15.1-27.fc7.ppc.rpm fbbe1ff700d6a4d213d950d18845b061b983f1d2 tar-1.15.1-27.fc7.ppc.rpm 2a0c359a2143728dfda85c1ab9e9bf7b09ff6b1e tar-1.15.1-27.fc7.src.rpm
This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://docs.fedoraproject.org/yum/.
Solution: Apply the appropriate updates.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-1890
Risk factor : High
CVSS Score: 6.8
|