Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21153-1

Опубликовано: 23 июн. 2026
Источник: suse-cvrf

Описание

Security update for xar

This update for xar fixes the following issues:

Changes in xar:

  • Switch to the maintained Apple xar lineage (build 503, versioned 1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's xar (apple-oss-distributions/xar). This resolves the long-standing NULL-pointer dereferences in xar_get_path() and xar_unserialize() when parsing malformed archives:
    • CVE-2017-11124 (boo#1047875)
    • CVE-2017-11125 (boo#1047874)
    • CVE-2018-17093 (boo#1108595)
    • CVE-2018-17094 (boo#1108596)

Список пакетов

openSUSE Leap 16.0
libxar-devel-1.8.0.0.503-bp160.1.1
libxar1-1.8.0.0.503-bp160.1.1
xar-1.8.0.0.503-bp160.1.1

Описание

libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.


Затронутые продукты
openSUSE Leap 16.0:libxar-devel-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:libxar1-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:xar-1.8.0.0.503-bp160.1.1

Ссылки

Описание

libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.


Затронутые продукты
openSUSE Leap 16.0:libxar-devel-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:libxar1-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:xar-1.8.0.0.503-bp160.1.1

Ссылки

Описание

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11125. Reason: This candidate is a duplicate of CVE-2017-11125. Notes: All CVE users should reference CVE-2017-11125 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage


Затронутые продукты
openSUSE Leap 16.0:libxar-devel-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:libxar1-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:xar-1.8.0.0.503-bp160.1.1

Ссылки

Описание

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11124. Reason: This candidate is a duplicate of CVE-2017-11124. Notes: All CVE users should reference CVE-2017-11124 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage


Затронутые продукты
openSUSE Leap 16.0:libxar-devel-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:libxar1-1.8.0.0.503-bp160.1.1
openSUSE Leap 16.0:xar-1.8.0.0.503-bp160.1.1

Ссылки