ELSA-2023-2898

ELSA-2023-2898 - libtar security update

Type:SECURITY
Severity:MODERATE
Release Date:2023-05-24

Description


[1.2.20-17]
- fix use-after-free bugs introduced by incorrect memleak fixes (CVE-2021-33640)

[1.2.20-16]
- fix memory leaks through gnu_long{name,link} (CVE-2021-33645 CVE-2021-33646)
- fix out-of-bounds read in gnu_long{name,link} (CVE-2021-33643 CVE-2021-33644)


Related CVEs


CVE-2021-33643
CVE-2021-33645
CVE-2021-33644
CVE-2021-33646

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) libtar-1.2.20-17.el8.src.rpm8085f20ebfd17323d31f89f448525a79-
libtar-1.2.20-17.el8.aarch64.rpmbe786fd4f2ec408ae3feff09cb6cb3ee-
Oracle Linux 8 (x86_64) libtar-1.2.20-17.el8.src.rpm8085f20ebfd17323d31f89f448525a79-
libtar-1.2.20-17.el8.i686.rpm165136dcc824f32a9c5384692af9cbc2-
libtar-1.2.20-17.el8.x86_64.rpm989b702843b02266ff1973e7a3c18dce-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete