Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 8: 2022-0060 Critical Updating of Libarchive Security Issues

mageia
Calendar Grey February 12, 2022
Dist Mageia Esm H88
Recent updates to libarchive packages resolve various security vulnerabilities identified in multiple CVEs, crucial for preserving the security of the system.
Processing fixup entries may follow symbolic links

Summary

Processing fixup entries may follow symbolic links. (CVE-2021-31566)
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). (CVE-2021-36976)

References

- https://bugs.mageia.org/show_bug.cgi?id=30023

- https://github.com/libarchive/libarchive/releases/tag/v3.5.3

- https://www.cve.org/CVERecord?id=CVE-2021-31566

- https://www.cve.org/CVERecord?id=CVE-2021-36976

Resolution

SRPMS

- 8/core/libarchive-3.5.3-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0060.html
Type: security
CVE: CVE-2021-31566, CVE-2021-36976

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here