Summary: | <app-arch/libarchive-3.2.1-r1: crash via malformed cpio archive (CVE-2015-8915) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | bsd+disabled, phmagic, ssuominen |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1216891 | ||
Whiteboard: | B3 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 586182 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() This is fixed in 3.2.1 as well. Added to existing GLSA. CVE assignment: http://seclists.org/oss-sec/2016/q2/566 Upstream bug https://github.com/libarchive/libarchive/issues/503 mentioned in the CVE assignment was identified as duplicate of /issues/502 from our comment #0. This issue was resolved and addressed in GLSA 201701-03 at https://security.gentoo.org/glsa/201701-03 by GLSA coordinator Thomas Deutschmann (whissi). |