[Bug 210493] archivers/libarchive: update to 3.2.1
bugzilla-noreply at freebsd.org
bugzilla-noreply at freebsd.org
Thu Jun 23 13:40:13 UTC 2016
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=210493
Bug ID: 210493
Summary: archivers/libarchive: update to 3.2.1
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Keywords: easy, patch, security
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: glewis at FreeBSD.org
Reporter: cmt at freebsd.org
Flags: maintainer-feedback?(glewis at FreeBSD.org),
maintainer-feedback?, merge-quarterly?
Assignee: glewis at FreeBSD.org
Created attachment 171710
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=171710&action=edit
update libarchive to 3.2.1
https://github.com/libarchive/libarchive/blob/master/NEWS
http://blog.talosintel.com/2016/06/the-poisoned-archives.html
https://groups.google.com/forum/#!topic/libarchive-announce/lyaOLoBI1Fs
libarchive 3.2.1 fixes several vulnerabilities including memory corruption and
code execution.
I'm attaching the update patch, poudriere log and vuln.xml fragment.
--
You are receiving this mail because:
You are the assignee for the bug.
More information about the freebsd-ports-bugs
mailing list