Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libarchive for openSUSE:Factory checked in at 2024-05-07 18:02:41 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libarchive (Old) and /work/SRC/openSUSE:Factory/.libarchive.new.1880 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libarchive" Tue May 7 18:02:41 2024 rev:50 rq:1172240 version:3.7.4 Changes: -------- --- /work/SRC/openSUSE:Factory/libarchive/libarchive.changes 2024-01-04 15:58:22.278653348 +0100 +++ /work/SRC/openSUSE:Factory/.libarchive.new.1880/libarchive.changes 2024-05-07 18:02:50.833292768 +0200 @@ -1,0 +2,28 @@ +Tue Apr 30 08:05:28 UTC 2024 - Danilo Spinella <[email protected]> + +- Update to 3.7.4: + * rar: Fix OOB in rar e8 filter (CVE-2024-26256, bsc#1222911) + * zip: Fix out of boundary access + * 7zip: Limit amount of properties + * bsdtar: Fix error handling around strtol() usages + * passphrase: Improve newline handling on Windows + * passphrase: Never allow empty passwords + * rar: Fix "File CRC Error" when extracting specific rar4 archives + * xar: Avoid infinite link loop + * zip: Update AppleDouble support for directories + * zstd: Implement core detection +- Update to 3.7.3: + * PCRE2 support + * add trailing letter b to bsdtar(1) substitute pattern + * add support for long options "--group" and "--owner" to tar(1) + * Fix possible vulnerability in tar error reporting introduced in f27c173 + * ISO9660: preserve the natural order of links + * rar5: fix decoding unicode filenames on Windows + * rar5: fix infinite loop if during rar5 decompression the last block produced no data + * xz filter: fix incorrect eof at the end of an lzip member + * zip: fix end-of-data marker processing when decompressing zip archives + * multiple bsdunzip(1) fixes + * filetime truncation fix on Windows +- Fix rpmlint warning about summary being too long + +------------------------------------------------------------------- Old: ---- libarchive-3.7.2.tar.xz libarchive-3.7.2.tar.xz.asc New: ---- libarchive-3.7.4.tar.xz libarchive-3.7.4.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libarchive.spec ++++++ --- /var/tmp/diff_new_pack.mm2MTd/_old 2024-05-07 18:02:51.473316040 +0200 +++ /var/tmp/diff_new_pack.mm2MTd/_new 2024-05-07 18:02:51.473316040 +0200 @@ -1,7 +1,7 @@ # # spec file for package libarchive # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2024 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -30,9 +30,9 @@ %bcond_without ext2fs %endif Name: libarchive -Version: 3.7.2 +Version: 3.7.4 Release: 0 -Summary: Utility and C library to create and read several different streaming archive formats +Summary: Utility and C library to create and read several streaming archive formats License: BSD-2-Clause Group: Productivity/Archiving/Compression URL: https://www.libarchive.org/ ++++++ libarchive-3.7.2.tar.xz -> libarchive-3.7.4.tar.xz ++++++ ++++ 20655 lines of diff (skipped)
