Debian Security Advisory
DSA-4360-1 libarchive -- security update
- Date Reported:
- 27 Dec 2018
- Affected Packages:
- libarchive
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-10209, CVE-2016-10349, CVE-2016-10350, CVE-2017-14166, CVE-2017-14501, CVE-2017-14502, CVE-2017-14503, CVE-2018-1000877, CVE-2018-1000878, CVE-2018-1000880.
- More information:
-
Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.
For the stable distribution (stretch), these problems have been fixed in version 3.2.2-2+deb9u1.
We recommend that you upgrade your libarchive packages.
For the detailed security status of libarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libarchive