You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke libarchive

Sigurnosni nedostaci programske biblioteke libarchive

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Gentoo Linux Security Advisory GLSA 201908-11
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
https://security.gentoo.org/
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Severity: Normal
Title: libarchive: Multiple vulnerabilities
Date: August 15, 2019
Bugs: #631294, #636070
ID: 201908-11

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Synopsis
========

Multiple vulnerabilities have been found in libarchive, the worst of
which could result in the arbitrary execution of code.

Background
==========

libarchive is a library for manipulating different streaming archive
formats, including certain tar variants, several cpio formats, and both
BSD and GNU ar variants.

Affected packages
=================

——————————————————————-
Package / Vulnerable / Unaffected
——————————————————————-
1 app-arch/libarchive < 3.3.3 >= 3.3.3

Description
===========

Multiple vulnerabilities have been discovered in libarchive. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All libarchive users should upgrade to the latest version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=app-arch/libarchive-3.3.3”

References
==========

[ 1 ] CVE-2017-14166
https://nvd.nist.gov/vuln/detail/CVE-2017-14166
[ 2 ] CVE-2017-14501
https://nvd.nist.gov/vuln/detail/CVE-2017-14501
[ 3 ] CVE-2017-14502
https://nvd.nist.gov/vuln/detail/CVE-2017-14502
[ 4 ] CVE-2017-14503
https://nvd.nist.gov/vuln/detail/CVE-2017-14503

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/201908-11

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users’ machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2019 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons – Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5

—–BEGIN PGP SIGNATURE—–

iQEzBAABCAAdFiEEDA48qNrrn8VVVcst4yp5f7HQy3AFAl1Vf0sACgkQ4yp5f7HQ
y3BlSwf/bt2ITX9uHfnglTff8rrAC2EWy2PKk6fuXT+Qr5Xh9RzG/QyzbhGlHvHr
ziOwLgR9yq+Q+CbOP5YjNhOPSgdr9xyGsWFW5bhYvsqi+kFBGiwN9F4Ssh/KC551
7mV++IWrrEA5bpeph96LWa3WkaAiBpmI5wCtd8T+TDHp/q2ORYUdWhjf8ioAZF0c
D4kxonm9uVf5SLxE8BpB+1mU+Y4pMiWB+niwYKEhPGJgECR4JarlwBs+l2NjJEhd
CL83T5e0q4CUO+0LUII1HOM92Kt1dP/GT4WJ5Yf6xrOuKzr8nEwhWBBTfShgBS6A
A11dwQ4d1dQoE/oJvwFegZMibrqfPg==
=gDKC
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa Mozilla Firefox

Otkriveni su sigurnosni nedostaci u programskom paketu Mozilla Firefox za operacijski sustav Gentoo. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvojnog...

Close