This update for xar fixes the following issues:
Changes in xar:
- Switch to the maintained Apple xar lineage (build 503, versioned
1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been
dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's
xar (apple-oss-distributions/xar). This resolves the long-standing
NULL-pointer dereferences in xar_get_path() and xar_unserialize()
when parsing malformed archives:
* CVE-2017-11124 (boo#1047875)
* CVE-2017-11125 (boo#1047874)
* CVE-2018-17093 (boo#1108595)
* CVE-2018-17094 (boo#1108596)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-348=1
- openSUSE Leap 16.0:
libxar-devel-1.8.0.0.503-bp160.1.1
libxar1-1.8.0.0.503-bp160.1.1
xar-1.8.0.0.503-bp160.1.1
* bsc#1047874
* bsc#1047875
* bsc#1108595
* bsc#1108596
References:
* https://www.suse.com/security/cve/CVE-2017-11124.html
* https://www.suse.com/security/cve/CVE-2017-11125.html
* https://www.suse.com/security/cve/CVE-2018-17093.html
* https://www.suse.com/security/cve/CVE-2018-17094.html
Get the latest Linux and open source security news straight to your inbox.