1,3 → 1,15 |
libtar (1.2.16-1+deb7u2) wheezy-security; urgency=low |
|
* [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any |
pathname prefix containing ".." components (Closes: #731860). This is |
done in th_get_pathname() (as well as to symlink targets when |
extracting symlinks), not merely when extracting files, which means |
applications calling that function will not see the stored |
filename. There is no way to disable this behaviour, but it can be |
expected that one will be provided when the issue is solved upstream. |
|
-- Magnus Holmgren <holmgren@debian.org> Sun, 16 Feb 2014 19:12:18 +0100 |
|
libtar (1.2.16-1+deb7u1) wheezy-security; urgency=low |
|
* [SECURITY] size_t-overflow_cve-2013-4397.patch: Fix CVE-2013-4397: |