Updated libarchive packages fix security vulnerabilities
Publication date: 06 Nov 2024Modification date: 06 Nov 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-48957 , CVE-2024-48958
Description
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. (CVE-2024-48957) execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. (CVE-2024-48958)
References
SRPMS
9/core
- libarchive-3.6.2-5.2.mga9