openSUSE Recommended Update: Recommended update for tar ______________________________________________________________________________ Announcement ID: openSUSE-RU-2016:3263-1 Rating: important References: #1012633 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that has one recommended fix can now be installed. Description: This update for tar fixes the following issues: - the previous version of tar fixed a security issue "POINTYFEATHER" (CVE-2016-6321, boo#1007188). This fix introduced a regression in functionality. It was not possible any more to add files an archive that contained '..' components (boo#1012633). Patch Instructions: To install this openSUSE Recommended Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-1518=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): tar-1.28-2.22.1 tar-backup-scripts-1.28-2.22.1 tar-debuginfo-1.28-2.22.1 tar-debugsource-1.28-2.22.1 tar-tests-1.28-2.22.1 tar-tests-debuginfo-1.28-2.22.1 - openSUSE 13.2 (noarch): tar-lang-1.28-2.22.1 References: https://bugzilla.suse.com/1012633