<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="63aee4198c31eb95a13c8b4dce895430"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2127">
  <id>dbg111-tar</id>
  <title>tar security update</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1268355572"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=579475" id="579475" title="bug number 579475" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624" id="CVE-2010-0624" title="CVE-2010-0624" type="cve"/>
  </references>
  <description>A malicious remote tape server could cause a buffer
overflow in tar. In order to exploit that an attacker would
have to trick the victim to extract a file that causes tar
to open a connection to the rmt server (CVE-2010-0624).
It's advisable to always use tar's
--force-local local option to avoid such tricks.
</description>
  <pkglist>
    <collection>
        <package name="tar-debuginfo" arch="i586" version="1.20" release="23.12.1">
          <filename>tar-debuginfo-1.20-23.12.1.i586.rpm</filename>
        </package>
        <package name="tar-debuginfo" arch="ppc" version="1.20" release="23.12.1">
          <filename>tar-debuginfo-1.20-23.12.1.ppc.rpm</filename>
        </package>
        <package name="tar-debuginfo" arch="x86_64" version="1.20" release="23.12.1">
          <filename>tar-debuginfo-1.20-23.12.1.x86_64.rpm</filename>
        </package>
        <package name="tar-debugsource" arch="i586" version="1.20" release="23.12.1">
          <filename>tar-debugsource-1.20-23.12.1.i586.rpm</filename>
        </package>
        <package name="tar-debugsource" arch="ppc" version="1.20" release="23.12.1">
          <filename>tar-debugsource-1.20-23.12.1.ppc.rpm</filename>
        </package>
        <package name="tar-debugsource" arch="x86_64" version="1.20" release="23.12.1">
          <filename>tar-debugsource-1.20-23.12.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
