libarchive issue ?

Cy Schubert Cy.Schubert at cschubert.com
Tue Nov 12 23:39:32 UTC 2019


In message <7a8b39d8-fd86-4d89-8893-4cf3bf34d447 at sentex.net>, mike tancsa 
write
s:
> Hi,
>
>     I was thinking with the 2 intel CPU SAs, there would be an SA fo
> libarchive issue ?
>
> https://nvd.nist.gov/vuln/detail/CVE-2019-18408
>
> Or is FreeBSD not vulnerable to this particular issue ? I think as fix was
>
> __FBSDID("$FreeBSD:
> stable/12/contrib/libarchive/libarchive/archive_read_support_filter_lz4.c
> 353375 2019-10-09 22:18:01Z mm $");
>
> but just wanted to make sure

Parsing the commit log messages, we're beyond 3.4.0. Looks like we're ok.


-- 
Cheers,
Cy Schubert <Cy.Schubert at cschubert.com>
FreeBSD UNIX:  <cy at FreeBSD.org>   Web:  http://www.FreeBSD.org

	The need of the many outweighs the greed of the few.




More information about the freebsd-security mailing list