DSA-3677-1 libarchive -- security update

Related Vulnerabilities: CVE-2016-5418   CVE-2016-6250   CVE-2016-7166  

Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library, which may lead to denial of service (memory consumption and application crash), bypass of sandboxing restrictions and overwrite arbitrary files with arbitrary data from an archive, or the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 3.1.2-11+deb8u3. We recommend that you upgrade your libarchive packages.

Debian Security Advisory

DSA-3677-1 libarchive -- security update

Date Reported:
25 Sep 2016
Affected Packages:
libarchive
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 837714.
In Mitre's CVE dictionary: CVE-2016-5418, CVE-2016-6250, CVE-2016-7166.
More information:

Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library, which may lead to denial of service (memory consumption and application crash), bypass of sandboxing restrictions and overwrite arbitrary files with arbitrary data from an archive, or the execution of arbitrary code.

For the stable distribution (jessie), these problems have been fixed in version 3.1.2-11+deb8u3.

We recommend that you upgrade your libarchive packages.