Fix for CVE-2022-36227. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e15be0091f 2022-12-19 01:14:07.970062 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 37 Version : 3.6.1 Release : 3.fc37 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Fix for CVE-2022-36227 --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Lukas Javorsky - 3.6.1-3 - Resolves: CVE-2022-36227 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144974 - CVE-2022-36227 libarchive: Null pointer dereference in archive_write.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144974 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e15be0091f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix for CVE-2022-26280. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bbb5ec21b2 2022-05-23 01:13:58.799003 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 36 Version : 3.5.3 Release : 2.fc36 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Fix for CVE-2022-26280 --------------------------------------------------------------------------------ChangeLog: * Wed May 18 2022 Lukas Javorsky - 3.5.3-2 - Resolves: CVE-2022-26280 --------------------------------------------------------------------------------References: [ 1 ] Bug #2071934 - CVE-2022-26280 libarchive: CVE-2022-26280 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2071934 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bbb5ec21b2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebase to version 3.4.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-d8278fe24d 2020-06-07 19:44:15.413885 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 31 Version : 3.4.3 Release : 1.fc31 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Rebase to version 3.4.3 --------------------------------------------------------------------------------ChangeLog: * Fri May 22 2020 Ondrej Dubaj - 3.4.3-1 - Rebased to version 3.4.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1805967 - CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1805967 [ 2 ] Bug #1812636 - CVE-2019-20509 libarchive: heap-based buffer overflow in archive_read_support_format_lha.c due to insufficient validation of UTF-16 input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1812636 [ 3 ] Bug #1837828 - libarchive-3.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1837828 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-d8278fe24d' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Automatic update for libarchive-3.4.2-1.fc32.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-235688c222 2020-03-20 00:14:28.620621 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 32 Version : 3.4.2 Release : 1.fc32 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Automatic update for libarchive-3.4.2-1.fc32. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 12 2020 Ondrej Dubaj - 3.4.2-1 - Rebased to version 3.4.2 * Wed Jan 29 2020 Fedora Release Engineering - 3.4.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Fri Aug 30 2019 FeRD (Frank Dana) - 3.4.0-1 - New upstream release, adds RAR5 and ZIPX support (readonly) - Drop upstreamed patches - Add upstreamed patch to fix test failure with libzstd-1.4.2 * Thu Jul 25 2019 Fedora Release Engineering - 3.3.3-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu Mar 28 2019 Pavel Raiskup - 3.3.3-7 - simplify libtool hacks * Tue Mar 19 2019 Ondrej Dubaj - 3.3.3-6 - applied various flaws (#1663893) * Tue Mar 19 2019 Ondrej Dubaj - 3.3.3-5 - applied CVE patches (#1690071) * Thu Mar 14 2019 Ondrej Dubaj - 3.3.3-4 - applied various flaws (#1672900) * Fri Feb 1 2019 Fedora Release Engineering - 3.3.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Nov 26 2018 Pavel Raiskup - 3.3.3-2 -fix some covscan issues (rhbz#1602575) - build-requires libzstd-devel (rhbz#1653046) * Tue Oct 23 2018 Pavel Raiskup - 3.3.3-1 - the latest upstream release * Wed Jul 18 2018 Pavel Raiskup - 3.3.2-3 - drop use of %ldconfig_scriptlets * Fri Jul 13 2018 Fedora Release Engineering - 3.3.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1787791 - libarchive-3.4.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1787791 [ 2 ] Bug #1801636 - CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1801636 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-235688c222' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.