[ubuntu/maverick-security] libarchive 2.8.4-1ubuntu0.10.10.1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Dec 19 14:03:36 UTC 2011


libarchive (2.8.4-1ubuntu0.10.10.1) maverick-security; urgency=low

  * SECURITY UPDATE: arbitrary code execution via iso9660 overflows
    - debian/patches/CVE-2011-1777.patch: correctly fail on out of memory
      conditions in libarchive/archive_read_support_format_iso9660.c.
    - CVE-2011-1777
  * SECURITY UPDATE: arbitrary code execution via tar overflows
    - debian/patches/CVE-2011-1778.patch: correctly fail on out of memory
      conditions in libarchive/archive_read_support_format_tar.c
    - CVE-2011-1778

Date: Fri, 09 Dec 2011 12:34:05 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/maverick/+source/libarchive/2.8.4-1ubuntu0.10.10.1
-------------- next part --------------
Format: 1.8
Date: Fri, 09 Dec 2011 12:34:05 -0500
Source: libarchive
Binary: libarchive-dev libarchive1 bsdtar bsdcpio
Architecture: source
Version: 2.8.4-1ubuntu0.10.10.1
Distribution: maverick-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 bsdcpio    - cpio(1) from FreeBSD, using libarchive
 bsdtar     - tar(1) from FreeBSD, using libarchive
 libarchive-dev - Single library to read/write tar, cpio, pax, zip, iso9660, etc.
 libarchive1 - Single library to read/write tar, cpio, pax, zip, iso9660, etc.
Changes: 
 libarchive (2.8.4-1ubuntu0.10.10.1) maverick-security; urgency=low
 .
   * SECURITY UPDATE: arbitrary code execution via iso9660 overflows
     - debian/patches/CVE-2011-1777.patch: correctly fail on out of memory
       conditions in libarchive/archive_read_support_format_iso9660.c.
     - CVE-2011-1777
   * SECURITY UPDATE: arbitrary code execution via tar overflows
     - debian/patches/CVE-2011-1778.patch: correctly fail on out of memory
       conditions in libarchive/archive_read_support_format_tar.c
     - CVE-2011-1778
Checksums-Sha1: 
 a221f0205ae97d393a50c21eaad4b98e854cf90c 2131 libarchive_2.8.4-1ubuntu0.10.10.1.dsc
 67d1c4744ee4d4562a9a3e42b38679254e676e1d 15923 libarchive_2.8.4-1ubuntu0.10.10.1.debian.tar.gz
Checksums-Sha256: 
 907579321ae2b4048afcd7e410e667a16e566b34158ec7be49b2051d11108bce 2131 libarchive_2.8.4-1ubuntu0.10.10.1.dsc
 5d600254a083ace59f27fc0b354a8aab895c3e2034ec590f31ef58d5f4e10a7e 15923 libarchive_2.8.4-1ubuntu0.10.10.1.debian.tar.gz
Files: 
 7dc37c51556e05b00f344769b85fb373 2131 libs optional libarchive_2.8.4-1ubuntu0.10.10.1.dsc
 bcdaf4f554c7f2274856cf500e28c563 15923 libs optional libarchive_2.8.4-1ubuntu0.10.10.1.debian.tar.gz
Original-Maintainer: Andreas Henriksson <andreas at fatal.se>


More information about the Maverick-changes mailing list