I know there are some Gentoo users out there, so I figured it would be good to post this if you guys haven't already heard of it. I didn't see that it was posted. Here is the full article, but just in case you wanted the source, the site is here .
GENTOO LINUX SECURITY ANNOUNCEMENT
- - --------------------------------------------------------------------
PACKAGE :tar
SUMMARY :directory-traversal vulnerability
DATE :2002-10-01 12:30 UTC
- - --------------------------------------------------------------------
OVERVIEW
The tar utility contain vulnerabilities which can allow
arbitrary files to be overwritten during archive extraction.
DETAIL
During testing by Redhat of the fix to GNU tar from the advisory below,
it was discovered that GNU tar 1.13.25 was still vulnerable to a
modified version of the same problem.
Read the full original advisory at
http://marc.theaimsgroup.com/?l=bugt...6364810666&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running
sys-apps/tar-1.13.25-r2 and earlier update their systems
as follows:
emerge rsync
emerge tar
emerge clean