Changelog for
tar-1.16-3tr.i586.rpm :
Fri Sep 7 14:00:00 2007 Nived Gopalan
1.16-3tr
- SECURITY Fix: A vulnerability has been reported in GNU tar, caused
due to an input validation error when extracting tar archives. This
can be exploited to extract files to arbitrary locations outside the
specified directory with the permissions of the user running GNU tar
by using the \"//..\" directory traversal sequence in a specially
crafted tar archive.
The Common Vulnerabilities and Exposures project has assigned the
name CVE-2007-4131 to this issue.
Mon Feb 26 13:00:00 2007 Nived Gopalan
- Rebuilt
Tue Nov 28 13:00:00 2006 Nived Gopalan 1.16-1tr
- New Upstream
- SECURITY Fix: Teemu Salmela has reported a security issue in GNU tar,
caused due to the \"extract_archive()\" function in extract.c and the
\"extract_mangle()\" function in mangle.c still processing the deprecated
\"GNUTYPE_NAMES\" record type containing symbolic links. This can be
exploited to overwrite arbitrary files.
The Common Vulnerabilities and Exposures project has assigned the
name CVE-2006-6097 to this issue.
Fri Feb 17 13:00:00 2006 Bipin S 1.15.1-5tr
- SECURITY Fix: Fixed Heap overlfow CVE-2006-0300.
Wed Mar 23 13:00:00 2005 Syed Shabir Zakiullah 1.15.1-3tr
- Splitted dds2tar to separate spec
Wed Mar 16 13:00:00 2005 Syed Shabir Zakiullah 1.15.1-2tr
- New Upstream for dds2tar
- Rebuilt against Official Glibc-2.3.4
Sat Mar 5 13:00:00 2005 Ajith Thampi 1.15.1-1tr
- New Upstream
Mon Sep 27 14:00:00 2004 Erlend Midttun 1.14-1tr
- New upstream.
Mon Dec 8 13:00:00 2003 Erlend Midttun 1.13.25-9tr
- Big rebuild.
Wed Jun 18 14:00:00 2003 Erlend Midttun 1.13.25-8tr
- Big rebuild.
Wed Apr 9 14:00:00 2003 Gerald Dachs 1.13.25-7gd
- Added PreReq on htmlinfo
Mon Mar 24 13:00:00 2003 Erlend Midttun 1.13.25-6em
- Rebuilt against glibc 2.3.2.
Thu Feb 27 13:00:00 2003 Erlend Midttun 1.13.25-5em
- Make setup quiet.
Wed Feb 26 13:00:00 2003 Goetz Bock tar-1.13.25-4bg
- changed package name to tar, and have the tar srpm provide dds2tar
Sat Feb 1 13:00:00 2003 Tor Hveem dds2tar-2.4.21-3th
- Fixed package Group
- added texinfo buildreq
Sat Nov 23 13:00:00 2002 Goetz Bock 2.4.21-2bn
- merged the changes from info to htmlinfo from TSL2.0
- removed the i18n files
- added patch5 and pach6 from redhat to tar
Mon Apr 15 14:00:00 2002 Goetz Bock 2.4.21-1bn
- rebuild with real release number
Thu Mar 14 13:00:00 2002 Goetz Bock
- Combi SRPM with dds2tar and tar
- dds2tar 2.4.21
- tar 1.13.25
- builded for Trustix BlackNet Edition
Wed Jan 9 13:00:00 2002 Tim Powers
- automated rebuild
- based on redhat\'s tar-1.13.25-2