FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-0624

This CVE name corresponds to:

Entered Topic
2010-03-24 gtar -- buffer overflow in rmt client

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-0624
Phase Assigned(20100211)

Description

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

References

Source Reference
BUGTRAQ 20101027 rPSA-2010-0070-1 cpio tar
MISC http://www.agrs.tu-berlin.de/index.php?id=78327
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=564368
CONFIRM https://issues.rpath.com/browse/RPL-3219
FEDORA FEDORA-2010-4309
FEDORA FEDORA-2010-4321
FEDORA FEDORA-2010-2895
FEDORA FEDORA-2010-4302
FEDORA FEDORA-2010-4306
GENTOO GLSA-201111-11
MANDRIVA MDVSA-2010:065
REDHAT RHSA-2010:0141
REDHAT RHSA-2010:0142
REDHAT RHSA-2010:0144
REDHAT RHSA-2010:0145
SUSE SUSE-SR:2010:011
OSVDB 62950
OVAL oval:org.mitre.oval:def:10277
OVAL oval:org.mitre.oval:def:6907
SECUNIA 38869
SECUNIA 38988
SECUNIA 39008
VUPEN ADV-2010-0628
VUPEN ADV-2010-0629
VUPEN ADV-2010-0639
VUPEN ADV-2010-0728
VUPEN ADV-2010-0729
VUPEN ADV-2010-0687
VUPEN ADV-2010-1107