An update that solves 2 vulnerabilities can now be installed.. # bsdtar-3.7.7-3.1 on GA media Announcement ID: openSUSE-SU-2025:14882-1 Rating: moderate Cross-References: * CVE-2025-1632 * CVE-2025-25724 CVSS scores: * CVE-2025-1632 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-1632 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-25724 ( SUSE ): 4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-25724 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the bsdtar-3.7.7-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * bsdtar 3.7.7-3.1 * libarchive-devel 3.7.7-3.1 * libarchive13 3.7.7-3.1 * libarchive13-32bit 3.7.7-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-1632.html * https://www.suse.com/security/cve/CVE-2025-25724.html . Update for openSUSE Tumbleweed resolves two security concerns in bsdtar package. Install the recommended patch promptly.. update, solves, vulnerabilities, installed, bsdtar-3, media, announc. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # bsdtar-3.7.7-2.1 on GA media Announcement ID: openSUSE-SU-2025:14844-1 Rating: moderate Cross-References: * CVE-2024-57970 CVSS scores: * CVE-2024-57970 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57970 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the bsdtar-3.7.7-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * bsdtar 3.7.7-2.1 * libarchive-devel 3.7.7-2.1 * libarchive13 3.7.7-2.1 * libarchive13-32bit 3.7.7-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-57970.html . A moderate security update has been issued for bsdtar on openSUSE. It is crucial to update to avoid potential threats due to identified vulnerabilities. bsdtar security, openSUSE update, advisory information, moderate rating, cross-reference issue. . LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for bsdtar ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:14233-1 Rating: moderate References: #1005070 #1059139 #985601 #985706 Cross-References: CVE-2015-8915 CVE-2015-8925 CVE-2016-8687 CVE-2017-14503 Affected Products: SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for bsdtar fixes the following issues: - CVE-2015-8915: Fixed an invalid read which could have allowed remote attackers to cause a denial of service (bsc#985601). - CVE-2015-8925: Fixed an invalid read which could have allowed remote attackers to cause a denial of service (bsc#985706). - CVE-2017-14503: Fixed an out of bounds read within lha_read_data_none() in archive_read_support_format_lha.c (bsc#1059139). - CVE-2016-8687: Fixed a buffer overflow when printing a filename (bsc#1005070). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-bsdtar-14233=1 Package List: - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): bsdtar-debuginfo-2.5.5-10.8.1 bsdtar-debugsource-2.5.5-10.8.1 References: https://www.suse.com/security/cve/CVE-2015-8915.html https://www.suse.com/security/cve/CVE-2015-8925.html https://www.suse.com/security/cve/CVE-2016-8687.html https://www.suse.com/security/cve/CVE-2017-14503.html https://bugzilla.suse.com/1005070 https://bugzilla.suse.com/1059139 https://bugzilla.suse.com/985601 https://bugzilla.suse.com/985706 _______________________________________________ sle-security-updates mailing list
An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.. SUSE Security Update: Security update for bsdtar ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:1939-1 Rating: important References: #920870 #984990 #985609 #985669 #985675 #985682 #985698 Cross-References: CVE-2015-2304 CVE-2015-8918 CVE-2015-8920 CVE-2015-8921 CVE-2015-8924 CVE-2015-8929 CVE-2016-4809 Affected Products: SUSE Studio Onsite 1.3 SUSE OpenStack Cloud 5 SUSE Manager Proxy 2.1 SUSE Manager 2.1 SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Server 11-SP2-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: bsdtar was updated to fix seven security issues. These security issues were fixed: - CVE-2015-8929: Memory leak in tar parser (bsc#985669). - CVE-2016-4809: Memory allocate error with symbolic links in cpio archives (bsc#984990). - CVE-2015-8920: Stack out of bounds read in ar parser (bsc#985675). - CVE-2015-8921: Global out of bounds read in mtree parser (bsc#985682). - CVE-2015-8924: Heap buffer read overflow in tar (bsc#985609). - CVE-2015-8918: Overlapping memcpy in CAB parser (bsc#985698). - CVE-2015-2304: Reject absolute paths in input mode of bsdcpio exactly when '..' is rejected (bsc#920870). Patch Instructions: To install this SUSE SecurityUpdate use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-bsdtar-12672=1 - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-bsdtar-12672=1 - SUSE Manager Proxy 2.1: zypper in -t patch slemap21-bsdtar-12672=1 - SUSE Manager 2.1: zypper in -t patch sleman21-bsdtar-12672=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-bsdtar-12672=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-bsdtar-12672=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-bsdtar-12672=1 - SUSE Linux Enterprise Server 11-SP2-LTSS: zypper in -t patch slessp2-bsdtar-12672=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-bsdtar-12672=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-bsdtar-12672=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.3 (x86_64): libarchive-devel-2.5.5-9.1 - SUSE OpenStack Cloud 5 (x86_64): libarchive2-2.5.5-9.1 - SUSE Manager Proxy 2.1 (x86_64): libarchive2-2.5.5-9.1 - SUSE Manager 2.1 (s390x x86_64): libarchive2-2.5.5-9.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libarchive-devel-2.5.5-9.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libarchive2-2.5.5-9.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): libarchive2-2.5.5-9.1 - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 s390x x86_64): libarchive2-2.5.5-9.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): libarchive2-2.5.5-9.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): bsdtar-debuginfo-2.5.5-9.1 bsdtar-debugsource-2.5.5-9.1 References: https://www.suse.com/security/cve/CVE-2015-2304.html https://www.suse.com/security/cve/CVE-2015-8918.html https://www.suse.com/security/cve/CVE-2015-8920.html https://www.suse.com/security/cve/CVE-2015-8921.html https://www.suse.com/security/cve/CVE-2015-8924.html https://www.suse.com/security/cve/CVE-2015-8929.html https://www.suse.com/security/cve/CVE-2016-4809.html https://bugzilla.suse.com/920870 https://bugzilla.suse.com/984990 https://bugzilla.suse.com/985609 https://bugzilla.suse.com/985669 https://bugzilla.suse.com/985675 https://bugzilla.suse.com/985682 https://bugzilla.suse.com/985698 . Resolves 7 vulnerabilities in SUSE concerning bsdtar software, enhancing overall system robustness and security.. bsdtar vulnerabilities, important security patch, memory management issues, SUSE update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.