Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59841
Category:Fedora Local Security Checks
Title:Fedora Core 8 FEDORA-2007-2800 (tar)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to tar
announced via advisory FEDORA-2007-2800.

The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive. Tar
can also be used to add supplemental files to an archive and to update
or list files in the archive. Tar includes multivolume support,
automatic archive compression/decompression, the ability to perform
remote archives, and the ability to perform incremental and full
backups.

If you want to use tar for remote backups, you also need to install
the rmt package.

ChangeLog:

* Wed Oct 24 2007 Radek Brich 2:1.17-4
- upstream patch for CVE-2007-4476
(tar stack crashing in safer_name_suffix)
References:

[ 1 ] Bug #280961 - CVE-2007-4476 tar stack crashing in safer_name_suffix
https://bugzilla.redhat.com/show_bug.cgi?id=280961
[ 2 ] CVE-2007-4476
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476
Updated packages:

9aa3db9f88424567eea01781c179b161f7a3ead0 tar-1.17-4.fc8.ppc64.rpm
9b027c40cdee9ba25102ff682956398cb94aace9 tar-debuginfo-1.17-4.fc8.ppc64.rpm
ee8f37d014a168a4e0446ab362801aa64e6e7175 tar-debuginfo-1.17-4.fc8.i386.rpm
bc7af5ac1e50c4fb5c9ad01268575e32cb63c569 tar-1.17-4.fc8.i386.rpm
63aafa7ff75aa7199be1f73959584cfff5992d2f tar-1.17-4.fc8.x86_64.rpm
2a21b51d787b0505441ee87eac3007c402757ad8 tar-debuginfo-1.17-4.fc8.x86_64.rpm
39bedd9860414c1869aa141819e7e87b7c0377c5 tar-1.17-4.fc8.ppc.rpm
04d638d90d0801b3c0f963a44d5f5cc0e8e57009 tar-debuginfo-1.17-4.fc8.ppc.rpm
8910e138a6c01fe2f7034bd7f8f63e4b9e635e5d tar-1.17-4.fc8.src.rpm

This update can be installed with the yum update program. Use
su -c 'yum update tar'
at the command line. For more information, refer to Managing Software
with yum, available at http://docs.fedoraproject.org/yum/.

Solution: Apply the appropriate updates.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-2800

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-4476
1021680
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021680.1-1
26445
http://www.securityfocus.com/bid/26445
26674
http://secunia.com/advisories/26674
26987
http://secunia.com/advisories/26987
27331
http://secunia.com/advisories/27331
27453
http://secunia.com/advisories/27453
27514
http://secunia.com/advisories/27514
27681
http://secunia.com/advisories/27681
27857
http://secunia.com/advisories/27857
28255
http://secunia.com/advisories/28255
29968
http://secunia.com/advisories/29968
32051
http://secunia.com/advisories/32051
33567
http://secunia.com/advisories/33567
39008
http://secunia.com/advisories/39008
ADV-2010-0628
http://www.vupen.com/english/advisories/2010/0628
ADV-2010-0629
http://www.vupen.com/english/advisories/2010/0629
DSA-1438
http://www.debian.org/security/2007/dsa-1438
DSA-1566
http://www.debian.org/security/2008/dsa-1566
FEDORA-2007-2673
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00370.html
FEDORA-2007-735
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00073.html
GLSA-200711-18
http://security.gentoo.org/glsa/glsa-200711-18.xml
MDKSA-2007:197
http://www.mandriva.com/security/advisories?name=MDKSA-2007:197
MDKSA-2007:233
http://www.mandriva.com/security/advisories?name=MDKSA-2007:233
RHSA-2010:0141
http://www.redhat.com/support/errata/RHSA-2010-0141.html
RHSA-2010:0144
http://www.redhat.com/support/errata/RHSA-2010-0144.html
SUSE-SR:2007:018
http://www.novell.com/linux/security/advisories/2007_18_sr.html
SUSE-SR:2007:019
http://www.novell.com/linux/security/advisories/2007_19_sr.html
USN-650-1
http://www.ubuntu.com/usn/usn-650-1
USN-709-1
http://www.ubuntu.com/usn/usn-709-1
http://bugs.gentoo.org/show_bug.cgi?id=196978
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
https://bugzilla.redhat.com/show_bug.cgi?id=280961
https://issues.rpath.com/browse/RPL-1861
oval:org.mitre.oval:def:7114
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7114
oval:org.mitre.oval:def:8599
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8599
oval:org.mitre.oval:def:9336
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9336
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.