Author: renodr
Date: Thu Jan 2 18:57:22 2020
New Revision: 1518
Log:
Add libarchive errata
Modified:
html/trunk/blfs/errata/9.0-systemd/index.html
html/trunk/blfs/errata/9.0/index.html
Modified: html/trunk/blfs/errata/9.0-systemd/index.html
==============================================================================
--- html/trunk/blfs/errata/9.0-systemd/index.html Thu Jan 2 14:48:19
2020 (r1517)
+++ html/trunk/blfs/errata/9.0-systemd/index.html Thu Jan 2 18:57:22
2020 (r1518)
@@ -166,6 +166,13 @@
update to node.js-12.14.0 as soon as possible using the instructions in
<a href="../../view/systemd/general/nodejs.html">Node.JS-12.14.0</a>.</p>
+ <p>After release, a series of security flaws was discovered in libarchive.
+ These include security fixes in the RAR5 reader, wide string processing,
+ optimizations to the write filter logic, and the use of readlink(2). To
fix
+ these vulnerabilities, update to libarchive-3.4.1 or later using the
+ instructions in
+ <a
href="../../view/systemd/general/libarchive.html">libarchive-3.4.1</a>.</p>
+
<h2>Known Security Vulnerabilities</h2>
<p>A few packages are good at reporting that a new
Modified: html/trunk/blfs/errata/9.0/index.html
==============================================================================
--- html/trunk/blfs/errata/9.0/index.html Thu Jan 2 14:48:19 2020
(r1517)
+++ html/trunk/blfs/errata/9.0/index.html Thu Jan 2 18:57:22 2020
(r1518)
@@ -171,6 +171,13 @@
update to node.js-12.14.0 as soon as possible using the instructions in
<a href="../../view/svn/general/nodejs.html">Node.JS-12.14.0</a>.</p>
+ <p>After release, a series of security flaws was discovered in libarchive.
+ These include security fixes in the RAR5 reader, wide string processing,
+ optimizations to the write filter logic, and the use of readlink(2). To
fix
+ these vulnerabilities, update to libarchive-3.4.1 or later using the
+ instructions in
+ <a href="../../view/svn/general/libarchive.html">libarchive-3.4.1</a>.</p>
+
<!--
<p>A vulnerability with available exploits in all recent versions of
ghostscript has been fixed in the development book by patching gs-9.25.
--
http://lists.linuxfromscratch.org/listinfo/website
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page