quoted
quoted
quoted
quoted
"Fabrice" == Fabrice Fontaine [off-list ref] writes:
> - Fix CVE-2020-9308: archive_read_support_format_rar5.c in libarchive
> before 3.4.2 attempts to unpack a RAR5 file with an invalid or
> corrupted header (such as a header size of zero), leading to a SIGSEGV
> or possibly unspecified other impact.
> - Add new mbedtls optional dependency and use --with-nettle to enable
> nettle support, see
> https://github.com/libarchive/libarchive/commit/f96a71144b7725ca4a94d84bd27d7dca8c2f58d2
> Signed-off-by: Fabrice Fontaine [off-list ref]
> ---
> Changes v1 -> v2:
> - Add --without-mbedtls to host variant
Committed to 2019.11.x, thanks.
According to https://security-tracker.debian.org/tracker/CVE-2020-9308,
the rar5 support was only added in 3.4.0, so the 3.3.3 version we have
in 2019.02.x is not affected.
--
Bye, Peter Korsgaard