-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 22 Nov 2006 20:21:52 -0800 Source: tar Binary: tar Architecture: hppa_translations hppa Version: 1.15.1-2ubuntu2.1 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/hppa Build Daemon Changed-By: Kees Cook Description: tar - GNU tar Changes: tar (1.15.1-2ubuntu2.1) dapper-security; urgency=low . * SECURITY UPDATE: files can be overwritten/renamed in any writable location in the filesystem via GNUTYPE_NAMES type. * src/extract.c: disable GNUTYPE_NAMES type processing by default since it allows for immediate symlink creation and renames. * src/common.h, src/tar.c: add --allow-name-mangling option to restore default behavior. * References http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0344.html Files: d91186c970fe0cd4c60f9ddcbe9f3aae 546132 base required tar_1.15.1-2ubuntu2.1_hppa.deb 0c7035d9587ac394a7c8138f80c7a6a8 745596 raw-translations - tar_1.15.1-2ubuntu2.1_hppa_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFFZTOC0N0xjzyQZEIRAgmYAJ4y3qVVxj/fSUkg7CTg7gr//BQMeQCfZXCm eNgDUOVR2umNMDE1OREj4/8= =eDY7 -----END PGP SIGNATURE-----