CVE-2019-18408 (https://nvd.nist.gov/vuln/detail/CVE-2019-18408): archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
Let's stabilize 3.4.0 then.
An automated check of this bug failed - repoman reported dependency errors (43 lines truncated): > dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]'] > dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: RDEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]'] > dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0/desktop) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
An automated check of this bug succeeded - the previous repoman errors are now resolved.
arm64 stable
amd64 stable
x86 stable
sparc stable
s390 stable
ppc64 stable
hppa stable
ppc stable
ia64 stable
arm stable
m68k stable
sh stable
Cleanup done.
New GLSA request filed.
This issue was resolved and addressed in GLSA 202003-28 at https://security.gentoo.org/glsa/202003-28 by GLSA coordinator Thomas Deutschmann (whissi).