MGASA-2021-0430 - Updated libarchive packages fix security vulnerability

Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0430.html
Type: security
Affected Mageia releases: 8

Fix handling of symbolic link ACLs on Linux.

Never follow symlinks when setting file flags on Linux.

Do not follow symlinks when processing the fixup list.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29431
- https://github.com/libarchive/libarchive/releases/tag/v3.5.2

SRPMS:
- 8/core/libarchive-3.5.2-1.mga8

Mageia 2021-0430: libarchive security update

Fix handling of symbolic link ACLs on Linux

Summary

Fix handling of symbolic link ACLs on Linux. Never follow symlinks when setting file flags on Linux. Do not follow symlinks when processing the fixup list.

References

- https://bugs.mageia.org/show_bug.cgi?id=29431

- https://github.com/libarchive/libarchive/releases/tag/v3.5.2

Resolution

MGASA-2021-0430 - Updated libarchive packages fix security vulnerability

SRPMS

- 8/core/libarchive-3.5.2-1.mga8

Severity
Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0430.html
Type: security

Related News