From debian-security Wed Mar 08 09:29:05 2006 From: Mathieu Roy Date: Wed, 08 Mar 2006 09:29:05 +0000 To: debian-security Subject: Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution Message-Id: <200603081029.06120 () eos ! attique ! ici> X-MARC-Message: https://marc.info/?l=debian-security&m=114181115319598 Le Mercredi 8 Mars 2006 10:17, Steve Kemp a écrit : > On Wed, Mar 08, 2006 at 09:41:39AM +0100, Mathieu Roy wrote: > > > Package : tar > > > Vulnerability : buffer overflow > > > Problem-Type : local(remote) > > > > What does mean > > local(remote) > > > > Does it means local... or remote? > > Local. But remote in the sense that you may receive a .tar file > from a remote source. > Ok, thanks for the input. Looks like oxymoron, a bit confusing though (but I have no proposal for alternative wording). -- Mathieu Roy + | Thalie : | Clio : | Euterpe : | +-----------------------------------------------------------+