USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could cause tar to fail to extract old archives that recorded a nonzero size for directory entries, resulting in a regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms.
1.34+dfsg-1ubuntu0.1.22.04.61.35+dfsg-3ubuntu0.41.35+dfsg-4ubuntu0.41.27.1-1ubuntu0.1+esm71.28-2.1ubuntu0.2+esm61.29b-2ubuntu0.4+esm41.30+dfsg-7ubuntu0.20.04.4+esm3