Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-12-SP2:GA
patchinfo.2786
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.2786
<patchinfo incident="2786"> <issue id="984990" tracker="bnc">VUL-1: CVE-2016-4809: libarchive,bsdtar: Memory allocate error with symbolic links in cpio archives</issue> <issue id="985609" tracker="bnc">VUL-0: CVE-2015-8924: bsdtar,libarchive: heap buffer read overflow in tar</issue> <issue id="985665" tracker="bnc">VUL-1: CVE-2015-8932: bsdtar,libarchive: compress handler left shifting larger than int size</issue> <issue id="985669" tracker="bnc">VUL-1: CVE-2015-8929: bsdtar,libarchive: minor memory leak in tar parser</issue> <issue id="985673" tracker="bnc">VUL-1: CVE-2015-8934: bsdtar,libarchive: out of bounds read in RAR</issue> <issue id="985675" tracker="bnc">VUL-1: CVE-2015-8920: bsdtar,libarchive: Stack out of bounds read in ar parser</issue> <issue id="985679" tracker="bnc">VUL-1: CVE-2015-8928: bsdtar,libarchive: Heap out of bounds read in mtree parser</issue> <issue id="985682" tracker="bnc">VUL-1: CVE-2015-8921: bsdtar,libarchive: Global out of bounds read in mtree parser</issue> <issue id="985685" tracker="bnc">VUL-1: CVE-2015-8922: bsdtar,libarchive: Null pointer access in 7z parser</issue> <issue id="985688" tracker="bnc">VUL-1: CVE-2015-8933: bsdtar,libarchive: Undefined behavior / signed integer overflow in TAR parser</issue> <issue id="985689" tracker="bnc">VUL-1: CVE-2015-8931: bsdtar,libarchive: Undefined behavior / signed integer overflow in mtree parser</issue> <issue id="985697" tracker="bnc">VUL-1: CVE-2015-8919: bsdtar,libarchive: Heap out of bounds read in LHA/LZH parser</issue> <issue id="985698" tracker="bnc">VUL-1: CVE-2015-8918: bsdtar,libarchive: Overlapping memcpy in CAB parser</issue> <issue id="985700" tracker="bnc">VUL-1: CVE-2015-8930: bsdtar,libarchive: Endless loop in ISO parser</issue> <issue id="985703" tracker="bnc">VUL-1: CVE-2015-8923: bsdtar,libarchive: Unclear crashes in ZIP parser</issue> <issue id="985704" tracker="bnc">VUL-1: CVE-2015-8926: bsdtar,libarchive: Null pointer access in RAR parser</issue> <issue id="985706" tracker="bnc">VUL-1: CVE-2015-8925: bsdtar,libarchive: Unclear invalid memory read in mtree parser</issue> <issue id="985826" tracker="bnc">VUL-0: CVE-2016-4301: bsdtar,libarchive: Stack buffer overflow in the mtree parse_device</issue> <issue id="985832" tracker="bnc">VUL-0: CVE-2016-4300: bsdtar,libarchive: Heap buffer overflow vulnerability in the 7zip read_SubStreamsInfo</issue> <issue id="985835" tracker="bnc">VUL-0: CVE-2016-4302: bsdtar,libarchive: Heap buffer overflow in the Rar decompression functionality</issue> <issue id="2015-8928" tracker="cve" /> <issue id="2015-8929" tracker="cve" /> <issue id="2015-8934" tracker="cve" /> <issue id="2016-4809" tracker="cve" /> <issue id="2016-4302" tracker="cve" /> <issue id="2015-8920" tracker="cve" /> <issue id="2015-8921" tracker="cve" /> <issue id="2015-8922" tracker="cve" /> <issue id="2015-8923" tracker="cve" /> <issue id="2015-8924" tracker="cve" /> <issue id="2015-8925" tracker="cve" /> <issue id="2015-8926" tracker="cve" /> <issue id="2015-8932" tracker="cve" /> <issue id="2016-4301" tracker="cve" /> <issue id="2015-8931" tracker="cve" /> <issue id="2016-4300" tracker="cve" /> <issue id="2015-8919" tracker="cve" /> <issue id="2015-8918" tracker="cve" /> <issue id="2015-8930" tracker="cve" /> <issue id="2015-8933" tracker="cve" /> <category>security</category> <rating>important</rating> <packager>adrianSuSE</packager> <description>libarchive was updated to fix 20 security issues. These security issues were fixed: - CVE-2015-8918: Overlapping memcpy in CAB parser (bsc#985698). - CVE-2015-8919: Heap out of bounds read in LHA/LZH parser (bsc#985697). - CVE-2015-8920: Stack out of bounds read in ar parser (bsc#985675). - CVE-2015-8921: Global out of bounds read in mtree parser (bsc#985682). - CVE-2015-8922: Null pointer access in 7z parser (bsc#985685). - CVE-2015-8923: Unclear crashes in ZIP parser (bsc#985703). - CVE-2015-8924: Heap buffer read overflow in tar (bsc#985609). - CVE-2015-8925: Unclear invalid memory read in mtree parser (bsc#985706). - CVE-2015-8926: NULL pointer access in RAR parser (bsc#985704). - CVE-2015-8928: Heap out of bounds read in mtree parser (bsc#985679). - CVE-2015-8929: Memory leak in tar parser (bsc#985669). - CVE-2015-8930: Endless loop in ISO parser (bsc#985700). - CVE-2015-8931: Undefined behavior / signed integer overflow in mtree parser (bsc#985689). - CVE-2015-8932: Compress handler left shifting larger than int size (bsc#985665). - CVE-2015-8933: Undefined behavior / signed integer overflow in TAR parser (bsc#985688). - CVE-2015-8934: Out of bounds read in RAR (bsc#985673). - CVE-2016-4300: Heap buffer overflow vulnerability in the 7zip read_SubStreamsInfo (bsc#985832). - CVE-2016-4301: Stack buffer overflow in the mtree parse_device (bsc#985826). - CVE-2016-4302: Heap buffer overflow in the Rar decompression functionality (bsc#985835). - CVE-2016-4809: Memory allocate error with symbolic links in cpio archives (bsc#984990). </description> <summary>Security update for libarchive</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor