Bug#874539: libarchive: CVE-2017-14166: heap-based buffer overflow in xml_data (archive_read_support_format_xar.c)

2017-09-08 Thread Chris Lamb
Hi, Curiously I can't reproduce this on sid. autopkgtest attached, but the result is: archive_read_open_filename() failed: Unrecognized archive format ASSERT:Status code expected:<226> but was:<0> ie. not a crash. (Maintainers, please consider adding this test to your package!) Regards,

Bug#874539: libarchive: CVE-2017-14166: heap-based buffer overflow in xml_data (archive_read_support_format_xar.c)

2017-09-06 Thread Salvatore Bonaccorso
Source: libarchive Version: 3.1.2-11 Severity: important Tags: upstream patch security Forwarded: https://github.com/libarchive/libarchive/issues/935 Hi, the following vulnerability was published for libarchive. CVE-2017-14166[0]: | libarchive 3.3.2 allows remote attackers to cause a denial of s