Advisories ยป MGASA-2020-0253

Updated libarchive packages fix security vulnerability

Publication date: 10 Jun 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-20509


Updated libarchive packages fix security vulnerability:

archive_read_support_format_lha.c in libarchive before 3.4.1 does not
ensure valid sizes for UTF-16 input, which allows remote attackers to
cause a denial of service (heap-based buffer over-read and application
crash) via a crafted LHA archive (CVE-2019-20509).

The libarchive package has been updated to version 3.4.3, fixing this
issue and other bugs.