openSUSE-SU-2019:1196-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1196-1
openSUSE-SU-2019:1196-1
Summary: Security update for libarchive
Details: This update for libarchive fixes the following issues: Security issues fixed: - CVE-2018-1000877: Fixed a double free vulnerability in RAR decoder (bsc#1120653) - CVE-2018-1000878: Fixed a Use-After-Free vulnerability in RAR decoder (bsc#1120654) - CVE-2018-1000879: Fixed a NULL Pointer Dereference vulnerability in ACL parser (bsc#1120656) - CVE-2018-1000880: Fixed an Improper Input Validation vulnerability in WARC parser (bsc#1120659) - CVE-2019-1000019: Fixed an Out-Of-Bounds Read vulnerability in 7zip decompression (bsc#1124341) - CVE-2019-1000020: Fixed an Infinite Loop vulnerability in ISO9660 parser (bsc#1124342) This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/TIJ7ZTUCNAB4P5RGZHQDF4OC3WRSBWO4/#TIJ7ZTUCNAB4P5RGZHQDF4OC3WRSBWO4, https://bugzilla.suse.com/1120653, https://bugzilla.suse.com/1120654, https://bugzilla.suse.com/1120656, https://bugzilla.suse.com/1120659, https://bugzilla.suse.com/1124341, https://bugzilla.suse.com/1124342, https://www.suse.com/security/cve/CVE-2018-1000877, https://www.suse.com/security/cve/CVE-2018-1000878, https://www.suse.com/security/cve/CVE-2018-1000879, https://www.suse.com/security/cve/CVE-2018-1000880, https://www.suse.com/security/cve/CVE-2019-1000019, https://www.suse.com/security/cve/CVE-2019-1000020
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/opensuse/libarchive&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
