-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 28 Aug 2007 09:45:12 -0700 Source: tar Binary: tar Architecture: i386_translations i386 Version: 1.15.1-2ubuntu2.2 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Kees Cook Description: tar - GNU tar Changes: tar (1.15.1-2ubuntu2.2) dapper-security; urgency=low . * SECURITY UPDATE: directory traversal with malicious tar files. * src/names.c: adjust dot dot checking, patched inline. * References CVE-2007-4131 Files: 4fc1e5062e85522e7ece4fc41348ffcc 519474 base required tar_1.15.1-2ubuntu2.2_i386.deb 8ed327f03c4a417e3623f1d9acb1f498 745612 raw-translations - tar_1.15.1-2ubuntu2.2_i386_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFG1GQg0N0xjzyQZEIRAtk1AJ0TH1hL2Sf6ryLhn+m9wndAtnZbKACghAWM p8sL45Hgq2uV8ln/NzaTKbs= =TkoS -----END PGP SIGNATURE-----