Thread (9 messages) 9 messages, 4 authors, 2020-05-08

[Buildroot] [PATCH v2, 1/3] package/libarchive: security bump to version 3.4.2

flat view

From: Peter Korsgaard <peter@korsgaard.com>
Date: 2020-03-14 17:39:16

quoted
quoted
quoted
quoted
"Fabrice" == Fabrice Fontaine [off-list ref] writes:
 > - Fix CVE-2020-9308: archive_read_support_format_rar5.c in libarchive
 >   before 3.4.2 attempts to unpack a RAR5 file with an invalid or
 >   corrupted header (such as a header size of zero), leading to a SIGSEGV
 >   or possibly unspecified other impact.
 > - Add new mbedtls optional dependency and use --with-nettle to enable
 >   nettle support, see
 >   https://github.com/libarchive/libarchive/commit/f96a71144b7725ca4a94d84bd27d7dca8c2f58d2

 > Signed-off-by: Fabrice Fontaine [off-list ref]
 > ---
 > Changes v1 -> v2:
 >  - Add --without-mbedtls to host variant

Committed to 2019.11.x, thanks.

According to https://security-tracker.debian.org/tracker/CVE-2020-9308,
the rar5 support was only added in 3.4.0, so the 3.3.3 version we have
in 2019.02.x is not affected.

-- 
Bye, Peter Korsgaard
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help