It is currently Sun May 19, 2013 7:21 pm

All times are UTC




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: [Fixed]Perl module Archive::Tar < 1.40, Directory Traversal
PostPosted: Fri Dec 12, 2008 12:35 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
According to Redhat bugzilla and GLSA-200812-10, CVE-2007-4829, a user-assisted remote attack against Archive::Tar isn't fixed before version 1.40:

SecurityFocus wrote:
Perl Archive::Tar module is prone to a directory-traversal vulnerability because it fails to validate user-supplied data.

A successful attack can allow the attacker to overwrite files on a computer in the context of the user running the affected application. Successful exploits may aid in further attacks.

Note that all applications using Perl Archive::Tar module may be affected.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=295021
http://rt.cpan.org/Public/Bug/Display.html?id=29517

In our perl 5.10 package in SNAPSHOT, the Archive::Tar version is 1.38...

!8!


Last edited by infwonder on Sun Dec 21, 2008 3:05 pm, edited 1 time in total.

 Profile Send private message  
 
 Post subject: Re: Perl module Archive::Tar < 1.40, Directory Traversal
PostPosted: Wed Dec 17, 2008 9:37 am 
Global Moderator
Global Moderator
User avatar

Joined: Mon Apr 10, 2006 12:43 pm
Posts: 4727
Location: Ath (Belgium)
Same like mplayer issue ;)


 Profile Send private message  
 
 Post subject: Re: Perl module Archive::Tar < 1.40, Directory Traversal
PostPosted: Sun Dec 21, 2008 2:49 pm 
Administrator
Administrator
User avatar

Joined: Fri Mar 10, 2006 8:52 am
Posts: 3731
Location: Nantes - France
fixed


 Profile Send private message  
 
 Post subject: Re: Perl module Archive::Tar < 1.40, Directory Traversal
PostPosted: Sun Dec 21, 2008 3:04 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Thank you! \!D/ :-[


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: