[ubuntu/precise-security] tar 1.26-4ubuntu1.2 (Accepted)
Steve Langasek
steve.langasek at canonical.com
Mon May 3 13:09:39 UTC 2021
tar (1.26-4ubuntu1.2) precise-security; urgency=medium
* SECURITY UPDATE: Infinite read loop
- debian/patches/CVE-2018-20482.patch: Add handling for short read
condition in sparse_dump_region() of src/sparse.c.
- CVE-2018-20482
* SECURITY UPDATE: NULL pointer dereference
- debian/patches/CVE-2019-9923.patch: Check for NULL return value from
find_next_block in src/sparse.c.
- CVE-2019-9923
Date: 2021-01-12 16:07:09.341056+00:00
Changed-By: Avital Ostromich <avital.ostromich at canonical.com>
Signed-By: Steve Langasek <steve.langasek at canonical.com>
https://launchpad.net/ubuntu/+source/tar/1.26-4ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Precise-changes
mailing list