CVE-2010-0624
CVE-2010-0624
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://osvdb.org/62950https://bugzilla.redhat.com/show_bug.cgi?id=564368http://secunia.com/advisories/38869http://secunia.com/advisories/38988