libarchive-3.3.3-3.el8

エラータID: AXSA:2022-3102:01

Release date: 
Wednesday, March 16, 2022 - 03:23
Subject: 
libarchive-3.3.3-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

* libarchive: extracting a symlink with ACLs modifies ACLs of target (CVE-2021-23177)
* libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive (CVE-2021-31566)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-23177
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-31566
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libarchive-3.3.3-3.el8.src.rpm
    MD5: 8c3869ab69587d261de91a921fc89398
    SHA-256: 90f06b18c6b67f763e97e96d0167fc74ed941232378ef2dfd5e80268e48cb72e
    Size: 6.26 MB

Asianux Server 8 for x86_64
  1. bsdtar-3.3.3-3.el8.x86_64.rpm
    MD5: ea5c4813785e9ec11280acfd09fccf23
    SHA-256: 718148cb12d96d4486e0d850d7828c7eb4a3d62bcc38a647ea982a2690d4b322
    Size: 69.73 kB
  2. libarchive-3.3.3-3.el8.x86_64.rpm
    MD5: ed58f076173fd6e132a8183376161c7b
    SHA-256: 5516240a767dfdbe5b6524df8a87760cb26e1bbb05118e81b16d2116b819675d
    Size: 358.86 kB
  3. libarchive-devel-3.3.3-3.el8.x86_64.rpm
    MD5: addea68ceb82fae07dd4d12fac1f1b14
    SHA-256: 75fd89d6f794c3a6160e69af8e6ba7172c3dc87053bd855b07fc12f25a7a3f99
    Size: 130.57 kB
  4. libarchive-3.3.3-3.el8.i686.rpm
    MD5: fd42cf9eaf27e2e66aea9c3e95df190b
    SHA-256: ec55b6f40bab1b3b26c2c89da0157a64b02ede5c90e1462070c251df462d837e
    Size: 400.12 kB
  5. libarchive-devel-3.3.3-3.el8.i686.rpm
    MD5: 23addd4606b06d2cf9eab634fcf2d988
    SHA-256: 7d9b7319adf2ee3b8087d8ae046a9dd02d3be7cf148d2eb7e74b4aeed84369ab
    Size: 130.59 kB