Univention Bugzilla – Bug 55464
libarchive: Multiple issues (5.0)
Last modified: 2022-11-30 13:28:01 CET
New Debian libarchive 3.3.3-4+deb10u2 fixes: This update addresses the following issues: * out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c (CVE-2019-19221) * extracting a symlink with ACLs modifies ACLs of target (CVE-2021-23177) * symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive (CVE-2021-31566)
--- mirror/ftp/pool/main/liba/libarchive/libarchive_3.3.3-4+deb10u1.dsc +++ apt/ucs_5.0-0-errata5.0-2/source/libarchive_3.3.3-4+deb10u2.dsc @@ -1,3 +1,23 @@ +3.3.3-4+deb10u2 [Mon, 21 Nov 2022 16:48:59 +0100] Sylvain Beucler <beuc@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * CVE-2019-19221: archive_wstring_append_from_mbs in archive_string.c + has an out-of-bounds read because of an incorrect mbrtowc or mbtowc + call. For example, bsdtar crashes via a crafted archive. + (Closes: #945287) + * CVE-2021-23177: an improper link resolution flaw while extracting an + archive can lead to changing the access control list (ACL) of the + target of the link. An attacker may provide a malicious archive to a + victim user, who would trigger this flaw when trying to extract the + archive. A local attacker may use this flaw to change the ACL of a + file on the system and gain more privileges. (Closes: #1001986) + * CVE-2021-31566: an improper link resolution flaw can occur while + extracting an archive leading to changing modes, times, access control + lists, and flags of a file outside of the archive. An attacker may + provide a malicious archive to a victim user, who would trigger this + flaw when trying to extract the archive. A local attacker may use this + flaw to gain more privileges in a system. (Closes: #1001990) + 3.3.3-4+deb10u1 [Sun, 27 Oct 2019 10:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: * Non-maintainer upload by the LTS team. <http://piuparts.knut.univention.de/5.0-2/#6737870426618099615>
OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-2] 8ea0a64688 Bug #55464: libarchive 3.3.3-4+deb10u2 doc/errata/staging/libarchive.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) [5.0-2] b1a9305c5a Bug #55464: libarchive 3.3.3-4+deb10u2 doc/errata/staging/libarchive.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x500>