Bug 57150 - tar: Multiple issues (5.0)
Summary: tar: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-7-errata
Assignee: Quality Assurance
QA Contact: Iván.Delgado
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-14 15:05 CET by Quality Assurance
Modified: 2024-03-27 13:56 CET (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-03-14 15:05:18 CET
New Debian tar 1.30+dfsg-6+deb10u1 fixes:
This update addresses the following issue:
1.30+dfsg-6+deb10u1 (Sat, 09 Mar 2024 20:25:46 +0200)
* Non-maintainer upload by the LTS Team.
* CVE-2023-39804: Incorrectly handling of extension attributes in PAX  archives
Comment 1 Quality Assurance univentionstaff 2024-03-14 16:00:18 CET
--- mirror/ftp/pool/main/t/tar/tar_1.30+dfsg-6.dsc
+++ apt/ucs_5.0-0-errata5.0-7/source/tar_1.30+dfsg-6+deb10u1.dsc
@@ -1,3 +1,9 @@
+1.30+dfsg-6+deb10u1 [Sat, 09 Mar 2024 20:25:46 +0200] Adrian Bunk <bunk@debian.org>:
+
+  * Non-maintainer upload by the LTS Team.
+  * CVE-2023-39804: Incorrectly handling of extension attributes
+    in PAX archives
+
 1.30+dfsg-6 [Tue, 23 Apr 2019 10:05:54 -0600] Bdale Garbee <bdale@gag.com>:
 
   * eliminate ancient prerm cleanup code that breaks with merged /usr, 

<http://piuparts.knut.univention.de/5.0-7/#948332449052194547>
Comment 2 Iván.Delgado univentionstaff 2024-03-27 09:22:35 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.0-7] ed73b31e36 Bug #57150: tar 1.30+dfsg-6+deb10u1
 doc/errata/staging/tar.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.0-7] df362766e9 Bug #57150: tar 1.30+dfsg-6+deb10u1
 doc/errata/staging/tar.yaml | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

[5.0-7] 0af54247bb Bug #57150: tar 1.30+dfsg-6+deb10u1
 doc/errata/staging/tar.yaml | 15 +++++++++++++++
 1 file changed, 15 insertions(+)
Comment 3 Christian Castens univentionstaff 2024-03-27 13:56:43 CET
<https://errata.software-univention.de/#/?erratum=5.0x1008>