Package        : tar
Version        : 1.27.1-2+deb8u2
CVE ID         : CVE-2018-20482
Debian Bug     : #917377

It was discovered that there was a potential denial of service
vulnerability in tar, the GNU version of the tar UNIX archiving
utility.

The --sparse argument looped endlessly if the file shrank whilst
it was being read. Tar would only break out of this endless loop
if the file grew again to (or beyond) its original end of file.

For Debian 8 "Jessie", this issue has been fixed in tar version
1.27.1-2+deb8u2.

We recommend that you upgrade your tar packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1623-1: tar security update

December 31, 2018
It was discovered that there was a potential denial of service vulnerability in tar, the GNU version of the tar UNIX archiving utility

Summary

For Debian 8 "Jessie", this issue has been fixed in tar version
1.27.1-2+deb8u2.

We recommend that you upgrade your tar packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : tar
Version : 1.27.1-2+deb8u2
CVE ID : CVE-2018-20482
Debian Bug : #917377

Related News