Mageia 2024-0346: libarchive Security Advisory Updates
Summary
execute_filter_audio in archive_read_support_format_rar.c in libarchive
before 3.7.5 allows out-of-bounds access via a crafted archive file
because src can move beyond dst. (CVE-2024-48957)
execute_filter_delta in archive_read_support_format_rar.c in libarchive
before 3.7.5 allows out-of-bounds access via a crafted archive file
because src can move beyond dst. (CVE-2024-48958)
References
- https://bugs.mageia.org/show_bug.cgi?id=33717
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-48957
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-48958
Resolution
MGASA-2024-0346 - Updated libarchive packages fix security vulnerabilities
SRPMS
- 9/core/libarchive-3.6.2-5.2.mga9
![Dist Mageia](/images/distros/dist-mageia.jpg)