CVE-2007-4476

Publication date 5 September 2007

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

Read the notes from the security team

Status

Package Ubuntu Release Status
cpio 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Fixed 2.8-1ubuntu2.2
7.04 feisty
Fixed 2.6-17ubuntu0.7.04.1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 2.6-10ubuntu0.3
tar 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Fixed 1.18-2ubuntu1.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 1.15.1-2ubuntu2.3

Notes


jdstrand

1.19 has the fixes, 1.18 as included in Gutsy does not

References

Related Ubuntu Security Notices (USN)

Other references