Mageia alert MGASA-2016-0318 (libarchive)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2016-0318: Updated libarchive packages fix security vulnerability | |
| Date: | Sun, 25 Sep 2016 13:42:20 +0200 | |
| Message-ID: | <20160925114220.8D88C9F792@duvel.mageia.org> |
MGASA-2016-0318 - Updated libarchive packages fix security vulnerability Publication date: 25 Sep 2016 URL: http://advisories.mageia.org/MGASA-2016-0318.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-5418 Description: The updated packages fix several security vulnerabilities: A flaw was found in the way libarchive handled hardlink archive entries of non-zero size. Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive. (CVE-2016-5418, issues #745 and #746) Very long pathnames evade symlink checks (issue#744) size_t underflow leading to out of bounds heap read in process_extra() / archive_read_support_format_zip.c (issue#770) stack-based buffer overflow in bsdtar_expand_char (util.c) (issue#767) libarchive can compress, but cannot decompress zip some files (issue#748) hang in tar parser (issue#731) References: - https://bugs.mageia.org/show_bug.cgi?id=19351 - https://rhn.redhat.com/errata/RHSA-2016-1844.html - https://github.com/libarchive/libarchive/issues/745 - https://github.com/libarchive/libarchive/issues/746 - https://github.com/libarchive/libarchive/issues/744 - https://github.com/libarchive/libarchive/issues/770 - https://github.com/libarchive/libarchive/issues/767 - https://github.com/libarchive/libarchive/issues/748 - https://github.com/libarchive/libarchive/issues/731 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5418 SRPMS: - 5/core/libarchive-3.2.1-1.2.mga5
