WatchMouse keeps watch for the latest security news and vulnerability reports. Check here on a regular basis for updates or sign up using the form on the right to receive our security news updates via email.

View a full list of the most recent vulnerabilities here.

 

GNU Tar and GNU Cpio Remote Buffer Overflow Vulnerability
15 Mar 2010
GNU Tar and GNU Cpio are prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.

An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.

This issue affects the following:

GNU Tar versions prior to 1.23
GNU Cpio versions prior to 2.11
Securityfocus.com