SCIENTIFIC-LINUX-ERRATA Archives

December 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 1 Dec 2011 14:13:13 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (36 lines)
Synopsis:    Moderate: libarchive security update
Issue Date:  2011-12-01
CVE Numbers: CVE-2010-4666


The libarchive programming library can create and read several different
streaming archive formats, including GNU tar and cpio. It can also read ISO
9660 CD-ROM images.

Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)

All libarchive users should upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications using libarchive must be restarted for this update to take
effect.

SL6:
  i386
     libarchive-2.8.3-3.el6_1.i686.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
     libarchive-devel-2.8.3-3.el6_1.i686.rpm
  x86_64
     libarchive-2.8.3-3.el6_1.i686.rpm
     libarchive-2.8.3-3.el6_1.x86_64.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.i686.rpm
     libarchive-debuginfo-2.8.3-3.el6_1.x86_64.rpm
     libarchive-devel-2.8.3-3.el6_1.i686.rpm
     libarchive-devel-2.8.3-3.el6_1.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2