[ubuntu/focal-updates] libtar 1.2.20-8ubuntu0.20.04.1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Mon Mar 31 16:29:37 UTC 2025


libtar (1.2.20-8ubuntu0.20.04.1) focal-security; urgency=medium

  * SECURITY UPDATE: Out of bounds read when header struct is 0
    - debian/patches/CVE-2021-33643_33644.patch: Ensure that sz is
    greater than 0.
    - CVE-2021-33643
    - CVE-2021-33644
  * SECURITY UPDATE: Memory leak from failing to free
    t->th_buf.gnu_longlink
    - debian/patches/CVE-2021-33645_33646.patch: fix memory leak
    - CVE-2021-33645
    - CVE-2021-33646

Date: 2025-03-31 11:53:16.109864+00:00
Changed-By: John Breton <john.breton at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/libtar/1.2.20-8ubuntu0.20.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list