DSA-4360-1 libarchive -- security update

Related Vulnerabilities: CVE-2016-10209   CVE-2016-10349   CVE-2016-10350   CVE-2017-14166   CVE-2017-14501   CVE-2017-14502   CVE-2017-14503   CVE-2018-1000877   CVE-2018-1000878   CVE-2018-1000880  

Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service. For the stable distribution (stretch), these problems have been fixed in version 3.2.2-2+deb9u1. We recommend that you upgrade your libarchive packages. For the detailed security status of libarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libarchive

Debian Security Advisory

DSA-4360-1 libarchive -- security update

Date Reported:
27 Dec 2018
Affected Packages:
libarchive
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-10209, CVE-2016-10349, CVE-2016-10350, CVE-2017-14166, CVE-2017-14501, CVE-2017-14502, CVE-2017-14503, CVE-2018-1000877, CVE-2018-1000878, CVE-2018-1000880.
More information:

Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.

For the stable distribution (stretch), these problems have been fixed in version 3.2.2-2+deb9u1.

We recommend that you upgrade your libarchive packages.

For the detailed security status of libarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libarchive