SUSE-SU-2018:3571-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3571-1
SUSE-SU-2018:3571-1
Summary: Security update for libarchive
Details: This update for libarchive fixes the following issues: - CVE-2017-14501: An out-of-bounds read flaw existed in parse_file_info in archive_read_support_format_iso9660.c when extracting a specially crafted iso9660 iso file, related to archive_read_format_iso9660_read_header. (bsc#1059139) - CVE-2017-14502: read_header in archive_read_support_format_rar.c suffered from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header. (bsc#1059134) - CVE-2017-14503: libarchive suffered from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16. (bsc#1059100)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183571-1/, https://bugzilla.suse.com/1059100, https://bugzilla.suse.com/1059134, https://bugzilla.suse.com/1059139, https://www.suse.com/security/cve/CVE-2017-14501, https://www.suse.com/security/cve/CVE-2017-14502, https://www.suse.com/security/cve/CVE-2017-14503
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
