Bugtraq: [slackware-security] libarchive (SSA:2016-145-01)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

[slackware-security] libarchive (SSA:2016-145-01)

New libarchive packages are available for Slackware 14.1 and -current to

fix a security issue.

Here are the details from the Slackware 14.1 ChangeLog:

+--------------------------+

patches/packages/libarchive-3.1.2-i486-2_slack14.1.txz: Rebuilt.

Patched an issue with Zip archive handling that could allow an attacker

to overwrite parts of the heap in a controlled fashion and execute

arbitrary code.

For more information, see:

http://ift.tt/1XUsvh4

(* Security fix *)

+--------------------------+

Where to find the new packages:

+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab

(http://osuosl.org) for donating FTP and rsync hosting

to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for

additional mirror sites near you.

Updated package for Slackware 14.1:

http://ift.tt/20A5kYl

barchive-3.1.2-i486-2_slack14.1.txz

Updated package for Slackware x86_64 14.1:

http://ift.tt/23GQu2H

libarchive-3.1.2-x86_64-2_slack14.1.txz

Updated package for Slackware -current:

http://ift.tt/20A5AXc

rchive-3.1.2-i586-3.txz

Updated package for Slackware x86_64 -current:

http://ift.tt/1XUrUvL

libarchive-3.1.2-x86_64-3.txz

MD5 signatures:

+-------------+

Slackware 14.1 package:

36d7ea07c94eb19c7bddbb6b14085995 libarchive-3.1.2-i486-2_slack14.1.txz

Slackware x86_64 14.1 package:

23098669ee8382889d926ef24ec00d91 libarchive-3.1.2-x86_64-2_slack14.1.txz

Slackware -current package:

0e1ce376d5fd570371e5ab98c9134d42 l/libarchive-3.1.2-i586-3.txz

Slackware x86_64 -current package:

666d5136d4648aba95a55920fb9411fe l/libarchive-3.1.2-x86_64-3.txz

Installation instructions:

+------------------------+

Upgrade the package as root:

# upgradepkg libarchive-3.1.2-i486-2_slack14.1.txz

+-----+

Slackware Linux Security Team

http://ift.tt/1yLfFre

security (at) slackware (dot) com [email concealed]

+-----------------------------------------------------------------------

-+

| To leave the slackware-security mailing list: |

+-----------------------------------------------------------------------

-+

| Send an email to majordomo (at) slackware (dot) com [email concealed] with this text in the body of |

| the email message: |

| |

| unsubscribe slackware-security |

| |

| You will get a confirmation message back containing instructions to |

| complete the process. Please do not reply to this email address. |

+-----------------------------------------------------------------------

-+

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1

iEYEARECAAYFAldFA2sACgkQakRjwEAQIjMI8gCbB2bY9PA8KtBqaAvgzAoAp1kG

Z/wAn3O4tzq9UXabb1/Z+uz4/I6ynJSJ

=SD0f

-----END PGP SIGNATURE-----

[ reply ]


from SecurityFocus Vulnerabilities http://ift.tt/1YYvmE7