Upstream has released version 3.5.3 on February, 8: https://github.com/libarchive/libarchive/releases/tag/v3.5.3
CC: (none) => nicolas.salgueroCVE: (none) => CVE-2021-31566, CVE-2021-36976Whiteboard: (none) => MGA8TOOSource RPM: (none) => libarchive-3.5.2-1.mga8.src.rpmAssignee: bugsquad => nicolas.salguero
Suggested advisory: ======================== The updated packages fix security vulnerabilities: Processing fixup entries may follow symbolic links. (CVE-2021-31566) libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). (CVE-2021-36976) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31566 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36976 https://github.com/libarchive/libarchive/releases/tag/v3.5.3 ======================== Updated packages in core/updates_testing: ======================== bsdcpio-3.5.3-1.mga8 bsdcat-3.5.3-1.mga8 bsdtar-3.5.3-1.mga8 lib(64)archive13-3.5.3-1.mga8 lib(64)archive-devel-3.5.3-1.mga8 from SRPM: libarchive-3.5.3-1.mga8.src.rpm
Assignee: nicolas.salguero => qa-bugsWhiteboard: MGA8TOO => (none)Status: NEW => ASSIGNEDVersion: Cauldron => 8
MGA8-64 Plasma on Lenovo B50 in Dutch No installation issues. ref bug 29431 for test cd Documenten $ ls bugs/ gnucash.dbm libcairo.txt libzapojit.txt mirror.readme OLVvSnieuw.dbm plib.txt SOFTWARE* tutorialredis.txt Charts/ hello.go libhiredis.txt log4j_t1.7z nodejstar.js OLVvSnieuw_fixed.dbm pocapachecompress/ testkicad/ volkstuintjes/ cryptest_v helloworld.java libtinyxml.txt lxmltxt node_modules/ package-lock.json qtwebengin.txt testmodel.dbm wiresh/ gmp.txt jetty/ libtox.txt main.js 'OKRA DATABANK OLV Smarten 22.11.2021.accdb'* php/ SFboeken.tc thumbnail.py ziekenhuis/ $ bsdtar -c -f ~/archtar * Opened archtar with ark, all looks OK $ cd ~/tmp/ $ bsdtar -x -f /home/tester8/archtar Checked contents of tmp: all files and folders are there OK.
Whiteboard: (none) => MGA8-64-OKCC: (none) => herman.viaene
Validating. Advisory in Comment 1.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0060.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED
Fedora has issued an advisory for this on February 24: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SE5NJQNM22ZE5Z55LPAGCUHSBQZBKMKC/