MGASA-2020-0127

Source
https://advisories.mageia.org/MGASA-2020-0127.html
Import Source
https://advisories.mageia.org/MGASA-2020-0127.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0127
Related
Published
2020-03-06T16:13:58Z
Modified
2020-03-06T15:45:34Z
Summary
Updated libarchive packages fix security vulnerabilities
Details

The updated packages fix several issues including security vulnerabilities:

In Libarchive 3.4.0, archivewstringappendfrommbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. (CVE-2019-19221)

archivereadsupportformatrar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. (CVE-2020-9308)

References
Credits

Affected packages