MGASA-2016-0179
Dashboard / Vulnerabilities / MGASA-2016-0179
Summary: Updated libarchive packages fix CVE-2016-1541
Details: Updated libarchive packages fix security vulnerability: Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive (CVE-2016-1541). The libarchive package has been updated to version 3.2.0, fixing this issue and other bugs.
References: https://advisories.mageia.org/MGASA-2016-0179.html, https://bugs.mageia.org/show_bug.cgi?id=18420, https://groups.google.com/forum/#!topic/libarchive-announce/qdeGf_DRvN4, https://www.debian.org/security/2016/dsa-3574
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/mageia/libarchive?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
