[ubuntu/xenial-security] tar 1.28-2.1ubuntu0.2 (Accepted)

Avital Ostromich avital.ostromich at canonical.com
Wed Jan 13 17:25:46 UTC 2021


tar (1.28-2.1ubuntu0.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Infinite read loop
    - debian/patches/Fix-CVE-2018-20482.patch: Add handling for short read
      condition in sparse_dump_region() of src/sparse.c.
    - CVE-2018-20482
  * SECURITY UPDATE: NULL pointer dereference
    - debian/patches/CVE-2019-9923.patch: Check for NULL return value from
      find_next_block in src/sparse.c.
    - CVE-2019-9923

Date: 2021-01-11 17:23:08.702683+00:00
Changed-By: Avital Ostromich <avital.ostromich at canonical.com>
https://launchpad.net/ubuntu/+source/tar/1.28-2.1ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list