Upstream information
Description
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".NVD CVSS v2 Base Score: 2.6 (AV:N/AC:H/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 145081 SUSE Security Advisories:- SUSE-SR:2006:005, published Fri, 03 Mar 2006 15:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12765 |
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 Open Enterprise Server |
| ul1.x86-64 ul1.ppc ul1.s390 ul1.ia64 sles9-nlpos.x86 YOU Patch Nr: 10903 |
| SUSE LINUX Retail Solution 8 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8 for AMD64 SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries SuSE Linux Enterprise Server 8 for IBM zSeries SuSE Linux Enterprise Server 8 for IPF SuSE Linux Openexchange Server 4 SuSE Linux School Server for i386 SuSE Linux Standard Server 8 UnitedLinux 1.0 |
| ul1.x86-64 ul1.ppc ul1.s390 ul1.ia64 sles9-nlpos.x86 YOU Patch Nr: 10903 |
