Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Moderate: libarchive on SL6.x i386/x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Thursday 1st December 2011 20:13:13 UTC (over 4 years ago)
Synopsis:    Moderate: libarchive security update
Issue Date:  2011-12-01
CVE Numbers: CVE-2010-4666


The libarchive programming library can create and read several different
streaming archive formats, including GNU tar and cpio. It can also read ISO
9660 CD-ROM images.

Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)

All libarchive users should upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using libarchive must be restarted for this update to take
effect.

SL6:
  i386
     libarchive-2.8.3-3.el6_1.i686.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
     libarchive-devel-2.8.3-3.el6_1.i686.rpm
  x86_64
     libarchive-2.8.3-3.el6_1.i686.rpm
     libarchive-2.8.3-3.el6_1.x86_64.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.x86_64.rpm
     libarchive-devel-2.8.3-3.el6_1.i686.rpm
     libarchive-devel-2.8.3-3.el6_1.x86_64.rpm

- Scientific Linux Development Team
 
CD: 3ms