Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Scientific Linux: CVE-2010-4666 Moderate: libarchive Buffer Overflow

Scientific Large Esm H500
Moderate: libarchive security update
Date: Thu, 1 Dec 2011 14:13:13 -0600
Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: libarchive on SL6.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis: Moderate: libarchive security update
Issue Date: 2011-12-01
CVE Numbers: CVE-2010-4666

The libarchive programming library can create and read several different
streaming archive formats, including GNU tar and cpio. It can also read ISO
9660 CD-ROM images.

Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)

All libarchive users should upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using libarchive must be restarted for this update to take
effect.

SL6:
 i386
 libarchive-2.8.3-3.el6_1.i686.rpm
 libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
 libarchive-devel-2.8.3-3.el6_1.i686.rpm
 x86_64
 libarchive-2.8.3-3.el6_1.i686.rpm
 libarchive-2.8.3-3.el6_1.x86_64.rpm
 libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
 libarchive-debuginfo-2.8.3-3.el6_1.x86_64.rpm
 libarchive-devel-2.8.3-3.el6_1.i686.rpm
 libarchive-devel-2.8.3-3.el6_1.x86_64.rpm

- Scientific Linux Development Team
Your message here