Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 35: 2022-9bb794c5f5 Moderate: Libarchive Rebase to Version 3.5.3

fedora
Calendar Grey February 24, 2022
Dist Fedora Esm H88
Libarchive update for Fedora 35 addresses security issues while enhancing archive handling functionalities.
Rebase to version 3.5.3

Summary

Libarchive is a programming library that can create and read several different

streaming archive formats, including most popular tar variants, several cpio

formats, and both BSD and GNU ar variants. It can also write shar archives and

read ISO9660 CDROM images and ZIP archives.

Rebase to version 3.5.3

* Mon Feb 14 2022 Lukas Javorsky - 3.5.3-1

- Rebase to version 3.5.3

[ 1 ] Bug #1984647 - CVE-2021-36976 libarchive: use-after-free in copy_string() [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1984647

[ 2 ] Bug #2024238 - CVE-2021-31566 libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2024238

su -c 'dnf upgrade --advisory FEDORA-2022-9bb794c5f5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 35
Version: 3.5.3
Release: 1.fc35
Summary: A library for handling streaming archive formats

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here