libarchive 3.7.5

On September 14, a corrective release 3.7.5 of the library libarchive, addressing many bugs and vulnerabilities. The library and associated utilities are written in C and distributed under the New BSD.

Vulnerability fixes:

  • multiple vulnerabilities identified with Microsoft SAST;
  • cpio: possible (fuzz-test) overflow in signed 64-bit intermediate values gid/uid/size/ino when parsing AFIO archives (a type of CPIO);
  • lzop: prevention of integer overflow;
  • rar4: prevention of copying overly large value into int in function copy_from_lzss_window_to_unp (CVE-2024-20696);
  • rar4: remote code execution (CVE-2024-26256, CVS-2024-26256);
  • rar4: OOB in audio and delta filters;
  • rar4: out of range when working with large files;
  • rar4: a check for out of range has been added to the rgb filter;
  • rar4: OOB when reading an archive with Unicode filenames inside;
  • rar5: the data ready cache is now cleared during buffer memory redistribution;
  • rpm: correct calculation of header sizes;
  • unzip: out of bounds and undefined memory content when unpacking (when selecting [r]ename) if there is EOF in the filename;
  • out of bounds in the mktemp function;
  • uu: OOB when processing strings longer than 34816 bytes.

Other archive reading errors in 7zip, ar, lha, shar, rar5, and xar formats have also been fixed. Numerous corrections for Windows OS have been made.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster