-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 28 Aug 2007 09:45:12 -0700 Source: tar Binary: tar Architecture: amd64_translations amd64 Version: 1.15.1-2ubuntu2.2 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Kees Cook Description: tar - GNU tar Changes: tar (1.15.1-2ubuntu2.2) dapper-security; urgency=low . * SECURITY UPDATE: directory traversal with malicious tar files. * src/names.c: adjust dot dot checking, patched inline. * References CVE-2007-4131 Files: 4c4e01e4b1935b8536082d52e743eced 532120 base required tar_1.15.1-2ubuntu2.2_amd64.deb 4d1b37ecf04b76f2e5895725f7bf86b5 745610 raw-translations - tar_1.15.1-2ubuntu2.2_amd64_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFG1Gtu0N0xjzyQZEIRAhK4AJ0TSyWYEEWX1z0kC+gHRbQTDONl3wCdFLJd 7iDFB7bElkEQ21SCs7l1IOQ= =HkWy -----END PGP SIGNATURE-----