New Debian libarchive 3.1.2-11+deb8u6 fixes: This update addresses the following issues: * libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive. (CVE-2018-1000877) * libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive. (CVE-2018-1000878)
--- mirror/ftp/4.2/unmaintained/component/4.2-5-errata/source/libarchive_3.1.2-11+deb8u5.dsc +++ apt/ucs_4.2-0-errata4.2-5/source/libarchive_3.1.2-11+deb8u6.dsc @@ -1,3 +1,12 @@ +3.1.2-11+deb8u6 [Fri, 21 Dec 2018 22:24:50 +0100] Markus Koschany <apo@debian.org>: + + * Non-maintainer upload by the LTS team. + * Fix CVE-2018-1000877 and CVE-2018-1000878: + Daniel Axtens discovered a double-free and use-after-free vulnerability + in libarchive's RAR decoder that can result in a denial-of-service + (application crash) or may have other unspecified impact when a malformed + RAR archive is processed. + 3.1.2-11+deb8u5 [Thu, 29 Nov 2018 21:01:09 +0100] Markus Koschany <apo@debian.org>: * Non-maintainer upload by the LTS team. <http://10.200.17.11/4.2-5/#2657342048020898213>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.2-5] 4c1e1ee23e Bug #48405: libarchive 3.1.2-11+deb8u6 doc/errata/staging/libarchive.yaml | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) [4.2-5] b46d21303a Bug #48405: libarchive 3.1.2-11+deb8u6 doc/errata/staging/libarchive.yaml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+)
<http://errata.software-univention.de/ucs/4.2/569.html>