Описание
Security update for libarchive
This update for libarchive fixes the following issues:
- CVE-2022-26280: Fixed out-of-bounds read via the component zipx_lzma_alone_init (bsc#1197634).
- CVE-2021-36976: Fixed use-after-free in copy_string (called from do_uncompress_block and process_block) (bsc#1188572).
- CVE-2017-5601: Fixed out-of-bounds memory access preventing denial-of-service (bsc#1197634, bsc#1189528).
Список пакетов
Image SLES15-SP4-Manager-Server-4-3
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAP
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAP-Azure
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAP-EC2
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAP-GCE
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAPCAL
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAPCAL-Azure
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAPCAL-EC2
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-SAPCAL-GCE
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAP-Azure
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAP-EC2
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAP-GCE
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAPCAL-Azure
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAPCAL-EC2
libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP5-SAPCAL-GCE
libarchive13-3.5.1-150400.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP4
libarchive-devel-3.5.1-150400.3.3.1
libarchive13-3.5.1-150400.3.3.1
SUSE Linux Enterprise Module for Development Tools 15 SP4
bsdtar-3.5.1-150400.3.3.1
openSUSE Leap 15.4
bsdtar-3.5.1-150400.3.3.1
libarchive-devel-3.5.1-150400.3.3.1
libarchive13-3.5.1-150400.3.3.1
libarchive13-32bit-3.5.1-150400.3.3.1
Ссылки
- Link for SUSE-SU-2022:1930-1
- E-Mail link for SUSE-SU-2022:1930-1
- SUSE Security Ratings
- SUSE Bug 1022528
- SUSE Bug 1188572
- SUSE Bug 1189528
- SUSE Bug 1197634
- SUSE CVE CVE-2017-5601 page
- SUSE CVE CVE-2021-36976 page
- SUSE CVE CVE-2022-26280 page
Описание
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Затронутые продукты
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:libarchive13-3.5.1-150400.3.3.1
Ссылки
- CVE-2017-5601
- SUSE Bug 1022528
- SUSE Bug 1189528
Описание
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Затронутые продукты
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:libarchive13-3.5.1-150400.3.3.1
Ссылки
- CVE-2021-36976
- SUSE Bug 1188572
Описание
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Затронутые продукты
Image SLES15-SP4-Manager-Server-4-3-Azure-llc:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:libarchive13-3.5.1-150400.3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:libarchive13-3.5.1-150400.3.3.1
Ссылки
- CVE-2022-26280
- SUSE Bug 1197634