This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.
The remote Red Hat host is missing a security update.
An updated perl-Archive-Tar package that fixes multiple security
issues is now available for Red Hat Enterprise Linux 4 and 5.
The Red Hat Security Response Team has rated this update as having
moderate security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from
the CVE link in the References section.
The Archive::Tar module provides a mechanism for Perl scripts to
manipulate tar archive files.
Multiple directory traversal flaws were discovered in the Archive::Tar
module. A specially crafted tar file could cause a Perl script, using
the Archive::Tar module to extract the archive, to overwrite an
arbitrary file writable by the user running the script.
This package upgrades the Archive::Tar module to version 1.39_01.
Refer to the Archive::Tar module's changes file, linked to in the
References, for a full list of changes.
Users of perl-Archive-Tar are advised to upgrade to this updated
package, which corrects these issues. All applications using the
Archive::Tar module must be restarted for this update to take effect.
See also :
Update the affected perl-Archive-Tar package.
Risk factor :
Medium / CVSS Base Score : 6.8
CVSS Temporal Score : 5.9
Public Exploit Available : true
Family: Red Hat Local Security Checks
Nessus Plugin ID: 47871 ()
Bugtraq ID: 26355
CVE ID: CVE-2007-4829
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.