MGASA-2020-0127

Source
https://advisories.mageia.org/MGASA-2020-0127.html
Import Source
https://advisories.mageia.org/MGASA-2020-0127.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0127
Related
Published
2020-03-06T16:13:58Z
Modified
2020-03-06T15:45:34Z
Summary
Updated libarchive packages fix security vulnerabilities
Details

The updated packages fix several issues including security vulnerabilities:

In Libarchive 3.4.0, archivewstringappendfrommbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. (CVE-2019-19221)

archivereadsupportformatrar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. (CVE-2020-9308)

References
Credits

Affected packages

Mageia:7 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/mageia/libarchive?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.0-1.1.mga7

Ecosystem specific

{
    "section": "core"
}