From owner-freebsd-security Thu Jun 6 19:28:45 2002 Delivered-To: freebsd-security@freebsd.org Received: from dan.emsphone.com (dan.emsphone.com [199.67.51.101]) by hub.freebsd.org (Postfix) with ESMTP id 55F4837B407; Thu, 6 Jun 2002 19:28:31 -0700 (PDT) Received: (from dan@localhost) by dan.emsphone.com (8.12.3/8.12.3) id g572SUmu049645; Thu, 6 Jun 2002 21:28:30 -0500 (CDT) (envelope-from dan) Date: Thu, 6 Jun 2002 21:28:30 -0500 From: Dan Nelson To: Trevor Johnson Cc: Maxim Sobolev , security@FreeBSD.ORG, current@FreeBSD.ORG Subject: Re: WARNING! New GNU Tar in 5-CURRENT could erroneously create world writeable dirs Message-ID: <20020607022829.GF21901@dan.emsphone.com> References: <200206062245.g56Mjq319565@vega.vega.com> <20020606210833.W28206-100000@blues.jpj.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20020606210833.W28206-100000@blues.jpj.net> User-Agent: Mutt/1.3.99i X-OS: FreeBSD 5.0-CURRENT X-message-flag: Outlook Error Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org In the last episode (Jun 06), Trevor Johnson said: > > I've just noticed that something wrong with the new tar in the base > > system (1.13.25) - when extracting some archives it creates 777 dirs, > > while permissions in the archive itself are OK (for example GNU make > > make-3.79.1.tar.gz - top level dir gets 777 as well as several > > other lowel level dirs). The issue is under investigation. > > The latest version on ftp://ftp.gnu.org/gnu/tar/ is 1.13. The ones on > ftp://alpha.gnu.org/gnu/tar/ (and everything else on that site) are > considered unstable. I suppose it's too late to suggest tar 1.13 as a > starting point, but maybe this could be kept in mind when importing other > GNU products. Tar 1.13 is 3 years old, and has many bugs (incremental backups are unusable, for example). -- Dan Nelson dnelson@allantgroup.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message