#21308 closed enhancement (fixed)
libarchive-3.7.8
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 19 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 19 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 19 months ago
Libarchive 3.7.8 is a bugfix and security release
Security fixes:
- tar reader: Handle truncation in the middle of a GNU long linkname CVE-2024-57970)
- unzip: fix null pointer dereference (CVE-2025-1632)
- tar reader: fix unchecked return value in list_item_verbose() (CVE-2025-25724)
Important bugfixes:
- 7zip reader: add SPARC and POWERPC filter support for non-LZMA compressors
- tar reader: Ignore ustar size when pax size is present
- tar writer: Fix bug when -s/a/b/ used more than once with b flag
- cpio: Fix a Y2038 bug on Windows
- libarchive: Handle ARCHIVE_FILTER_LZOP in archive_read_append_filter
- libarchive: Adding missing seeker function to archive_read_open_FILE()
comment:4 by , 19 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
aa5ce0ed6a Update to libusb-1.0.28. 1b43bce9c1 Update to libarchive-3.7.8 (Security update). 384d2050f6 Update to libidn-1.43. 48773d0cd9 Update to libsoup-3.6.5.
comment:5 by , 17 months ago
SA-12.3-008 issued, with the caveat of recommending libarchive-3.7.9 due to a serious regression in the TAR functionality introduced by this update.
Note:
See TracTickets
for help on using tickets.

Marked as elevated due to a trio of medium-severity security fixes upstream