SUSE-SU-2022:1930-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1930-1
SUSE-SU-2022:1930-1
Summary: Security update for libarchive
Details: This update for libarchive fixes the following issues: - CVE-2022-26280: Fixed out-of-bounds read via the component zipx_lzma_alone_init (bsc#1197634). - CVE-2021-36976: Fixed use-after-free in copy_string (called from do_uncompress_block and process_block) (bsc#1188572). - CVE-2017-5601: Fixed out-of-bounds memory access preventing denial-of-service (bsc#1197634, bsc#1189528).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221930-1/, https://bugzilla.suse.com/1022528, https://bugzilla.suse.com/1188572, https://bugzilla.suse.com/1189528, https://bugzilla.suse.com/1197634, https://www.suse.com/security/cve/CVE-2017-5601, https://www.suse.com/security/cve/CVE-2021-36976, https://www.suse.com/security/cve/CVE-2022-26280
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
