Opened 19 months ago

Closed 19 months ago

Last modified 17 months ago

#21308 closed enhancement (fixed)

libarchive-3.7.8

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Douglas R. Reno, 19 months ago

Priority: normal → elevated

Marked as elevated due to a trio of medium-severity security fixes upstream

comment:2 by Bruce Dubbs, 19 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 19 months ago

Libarchive 3.7.8 is a bugfix and security release

Security fixes:

  • tar reader: Handle truncation in the middle of a GNU long linkname CVE-2024-57970)
  • unzip: fix null pointer dereference (CVE-2025-1632)
  • tar reader: fix unchecked return value in list_item_verbose() (CVE-2025-25724)

Important bugfixes:

  • 7zip reader: add SPARC and POWERPC filter support for non-LZMA compressors
  • tar reader: Ignore ustar size when pax size is present
  • tar writer: Fix bug when -s/a/b/ used more than once with b flag
  • cpio: Fix a Y2038 bug on Windows
  • libarchive: Handle ARCHIVE_FILTER_LZOP in archive_read_append_filter
  • libarchive: Adding missing seeker function to archive_read_open_FILE()

comment:4 by Bruce Dubbs, 19 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

aa5ce0ed6a Update to libusb-1.0.28.
1b43bce9c1 Update to libarchive-3.7.8 (Security update).
384d2050f6 Update to libidn-1.43.
48773d0cd9 Update to libsoup-3.6.5.

comment:5 by Douglas R. Reno, 17 months ago

SA-12.3-008 issued, with the caveat of recommending libarchive-3.7.9 due to a serious regression in the TAR functionality introduced by this update.

Note: See TracTickets for help on using tickets.