SUSE-SU-2016:1939-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1939-1
SUSE-SU-2016:1939-1
Summary: Security update for bsdtar
Details: bsdtar was updated to fix seven security issues. These security issues were fixed: - CVE-2015-8929: Memory leak in tar parser (bsc#985669). - CVE-2016-4809: Memory allocate error with symbolic links in cpio archives (bsc#984990). - CVE-2015-8920: Stack out of bounds read in ar parser (bsc#985675). - CVE-2015-8921: Global out of bounds read in mtree parser (bsc#985682). - CVE-2015-8924: Heap buffer read overflow in tar (bsc#985609). - CVE-2015-8918: Overlapping memcpy in CAB parser (bsc#985698). - CVE-2015-2304: Reject absolute paths in input mode of bsdcpio exactly when '..' is rejected (bsc#920870).
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161939-1/, https://bugzilla.suse.com/920870, https://bugzilla.suse.com/984990, https://bugzilla.suse.com/985609, https://bugzilla.suse.com/985669, https://bugzilla.suse.com/985675, https://bugzilla.suse.com/985682, https://bugzilla.suse.com/985698, https://www.suse.com/security/cve/CVE-2015-2304, https://www.suse.com/security/cve/CVE-2015-8918, https://www.suse.com/security/cve/CVE-2015-8920, https://www.suse.com/security/cve/CVE-2015-8921, https://www.suse.com/security/cve/CVE-2015-8924, https://www.suse.com/security/cve/CVE-2015-8929, https://www.suse.com/security/cve/CVE-2016-4809
Affected packages
Package
Name: bsdtar
Purl: pkg:rpm/suse/bsdtar&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
