DSA-3180-1 libarchive -- security update

Related Vulnerabilities: CVE-2015-2304  

Alexander Cherepanov discovered that bsdcpio, an implementation of the cpio program part of the libarchive project, is susceptible to a directory traversal vulnerability via absolute paths. For the stable distribution (wheezy), this problem has been fixed in version 3.0.4-3+wheezy1. For the upcoming stable distribution (jessie), this problem has been fixed in version 3.1.2-11. For the unstable distribution (sid), this problem has been fixed in version 3.1.2-11. We recommend that you upgrade your libarchive packages.

Debian Security Advisory

DSA-3180-1 libarchive -- security update

Date Reported:
05 Mar 2015
Affected Packages:
libarchive
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 778266.
In Mitre's CVE dictionary: CVE-2015-2304.
More information:

Alexander Cherepanov discovered that bsdcpio, an implementation of the cpio program part of the libarchive project, is susceptible to a directory traversal vulnerability via absolute paths.

For the stable distribution (wheezy), this problem has been fixed in version 3.0.4-3+wheezy1.

For the upcoming stable distribution (jessie), this problem has been fixed in version 3.1.2-11.

For the unstable distribution (sid), this problem has been fixed in version 3.1.2-11.

We recommend that you upgrade your libarchive packages.