Commit Graph

65 Commits

Author SHA1 Message Date
naddy
c1ff722c4b SECURITY:
Fix a directory traversal vulnerability. (CVE-2007-4131)
2007-09-01 21:05:21 +00:00
naddy
850f4da52a maintenance update to 1.18, only noteworthy change is switch to GPLv3 2007-08-25 19:49:01 +00:00
naddy
362a03027a Update to 1.17. Changes in this release:
* Fix archivation of sparse files in posix mode.
* Fix operation of --verify --listed-incremental.
* Fix --occurrence.
* Scope of --transform and --strip-components options.
* End-of-volume script can send the new volume name to tar.
2007-06-10 19:27:18 +00:00
espie
470294650d base64 distinfo with SHA256 2007-04-05 15:37:40 +00:00
sturm
c051d459d6 the static FLAVOR needs gettext to build as well 2006-12-23 20:24:42 +00:00
naddy
5615100fa3 Update to 1.16.1. User-visible changes:
* New option --exclude-tag allows to specify "exclusion tag files".
* The --exclude-cache option now excludes the directories themselves, too.
* Support for reading ustar type 'N' logical records has been removed.
* Race conditions around 'tar -x --same-owner' have been fixed.
2006-12-14 20:29:00 +00:00
naddy
e448c78a4a SECURITY:
GNU tar allows user-assisted attackers to overwrite arbitrary files
via a tar file that contains a GNUTYPE_NAMES record with a symbolic
link. (CVE-2006-6097)
2006-11-30 20:37:29 +00:00
naddy
37fdb40795 update to 1.16 2006-11-13 16:25:10 +00:00
naddy
d5b99a068f SECURITY:
A buffer overflow allows user-complicit attackers to cause a denial
of service (application crash) and possibly execute code via
unspecified vectors involving PAX extended headers.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300

Fix via Ubuntu (ultimately from upstream CVS).

ok pvalchev@
2006-02-27 21:29:55 +00:00
naddy
74ed91d09d Fix large sparse file corruption.
From bug-tar mailing list via Han Boetes <han@mijncomputer.nl>.
2006-01-11 16:40:51 +00:00
alek
ada27988e7 - Fix WANTLIB marker for -static FLAVOR
- Bump PKGNAME
2005-07-03 22:42:20 +00:00
espie
849fbd8002 FAKE=all + @endfake 2005-04-23 15:29:45 +00:00
naddy
5400bfd4d1 Fix command line parsing; from GNU CVS. 2005-01-30 14:56:57 +00:00
naddy
69777e8169 SIZE 2005-01-05 15:40:35 +00:00
naddy
1e90401cd6 Update to 1.15.1.
- Compressed archives are now recognized automatically.
- Numerous bug fixes.
2005-01-01 23:47:43 +00:00
espie
056bf5d790 Mark all system libs in WANTLIB, result of running newlib-depends-check 2004-11-21 12:50:32 +00:00
naddy
f25ca6486a Don't bother advertising GNU rmt. 2004-09-23 16:49:56 +00:00
espie
e370816909 four more common locale dirs. 2004-08-05 16:14:48 +00:00
espie
2df369f14f pass things through new make-plist 2004-08-04 16:22:59 +00:00
espie
e990387db0 switch to new style MODULES 2004-08-03 09:24:50 +00:00
naddy
69bf66944f correctly set MODGNU_CONFIG_GUESS_DIRS 2004-07-31 15:36:46 +00:00
espie
d51143282a switch to using dir/ and @info.
a few more tweaks done by the automatic update mode of make update-plist.
2004-07-24 14:20:48 +00:00
naddy
d01a6d3906 update to 1.14 2004-05-15 12:57:34 +00:00
naddy
bcb59cf546 Update to 1.13.94:
- Added support for POSIX.1-2001 and ustar archive formats.
- Various option cleanups.
- New message translations.
- Bug fixes.

Switch to .bz2 distfile since we already depend on bzip2 anyway.
2004-04-22 02:56:10 +00:00
naddy
cbdc3f441f @dirrm for shared directories 2003-12-15 15:49:08 +00:00
sturm
5b293eeb3d (void *)NULL 2003-10-26 17:22:24 +00:00
jolan
c19dced2a8 # GPL 2003-05-24 01:33:19 +00:00
brad
317d1a5f0a Fix a directory traversal vulnerability in GNU tar 1.13.25 which allows
attackers to overwrite arbitrary files durring extraction via a ".."
in an extracted filename.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0399
2002-10-01 02:03:52 +00:00
nino
15ead60a69 Add missing quotation marks. Ok naddy@. 2002-08-10 23:48:38 +00:00
espie
e3edfb9aea md5->distinfo 2002-03-21 20:20:41 +00:00
naddy
e677b23011 Update to 1.13.25:
* New option --overwrite-dir.
* Fixes for buffer overrun, porting, and copyright notice problems.
2001-11-05 00:58:29 +00:00
brad
e6b71a3503 use iconv or gettext module 2001-09-23 05:32:18 +00:00
naddy
881b3007a0 - update to 1.13.23; input from todd@
- fix install of info docs
2001-09-19 17:30:44 +00:00
naddy
997a37376c Update to 1.13.22. Note:
- The semantics for excludes have changed, and new options have
  been added in this area.
- bzip2 filtering has stabilized at -j.
2001-09-15 14:50:08 +00:00
naddy
d941b46eca document available flavors 2001-08-01 00:39:05 +00:00
brad
1953a9ae7f bump NEED_VERSION 2001-04-20 17:35:31 +00:00
brad
3ae2d1aa7a - integrate COMMENT
- bump NEED_VERSION
2001-03-29 15:01:53 +00:00
naddy
a5cdf07c97 Update to 1.13.19; improve DESCR.
Partly from Cyrille Lefevre <clefevre@citeweb.net> via FreeBSD.
2001-01-22 00:13:32 +00:00
naddy
d07f000718 Update to 1.13.18.
Since the GNU project seems to have abandoned the idea of releases, we might
as well integrate nine months of bug fixes.
2000-12-21 19:38:11 +00:00
naddy
221e6c22a8 - claim maintainership; ok niklas@, brad@
- add further master sites
2000-09-27 22:09:34 +00:00
brad
c520ae706e upgrade to GNU tar 1.13.17; most of this came from naddy@ 2000-09-27 20:11:37 +00:00
brad
0c7a16985e add #!/bin/sh 2000-07-19 09:31:17 +00:00
brad
a627238650 - remove FAKE=Yes
- add @comment with RCS id to PLIST
- HAS_CONFIGURE/GNU_CONFIGURE -> CONFIGURE_STYLE
- remove NO_CONFIGURE, NO_PATCH
- use new framework for PLISTs
2000-06-10 20:22:13 +00:00
turan
b2bb4f9664 add build_depend for gettext. msgfmt is required. 2000-04-09 07:17:23 +00:00
brad
3d6a8a8ede remove unnecessary post-install target, the binary is stripped anyway when
installed with "install"
2000-03-30 23:04:10 +00:00
espie
737d9536af Fake, separate_build for gtar. 2000-03-30 22:07:39 +00:00
espie
0fd05ef2ce Move all NEED_VERSION right after CATEGORY 2000-03-24 22:11:32 +00:00
turan
504f314d16 espie will not shut up about this, DISTF -> DISTFILES, PKG -> PACKAGE 2000-02-15 05:03:51 +00:00
turan
1574b9aa2e gpl licenses 2000-02-12 08:02:07 +00:00
brad
ded7e914be re-add post-extract target 2000-01-01 00:42:12 +00:00