[ubuntu/artful-proposed] libarchive 3.2.2-3.1 (Accepted)

Jeremy Bicha jeremy at bicha.net
Thu Sep 14 22:45:24 UTC 2017


libarchive (3.2.2-3.1) unstable; urgency=high

  * Non-maintainer upload.
  * Reupload 3.2.2-2.1 on top of 3.2.2-3
  * archive_strncat_l(): allocate and do not convert if length == 0
    (CVE-2016-10209) (Closes: #859456)
  * Reread the CAB header skipping the self-extracting binary code
    (CVE-2016-10349, CVE-2016-10350) (Closes: #861609)
  * Do something sensible for empty strings to make fuzzers happy
    (CVE-2017-14166)
    Fixes heap-based buffer over-read in the atol8 function. (Closes: #874539)

Date: 2017-09-14 22:34:17.654335+00:00
Changed-By: Peter Pentchev <roam at ringlet.net>
Signed-By: Jeremy Bicha <jeremy at bicha.net>
https://launchpad.net/ubuntu/+source/libarchive/3.2.2-3.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Artful-changes mailing list