[Buildroot] [PATCH-2019.02.x] package/libarchive: add upstream security fix for CVE-2019-18408
Peter Korsgaard
peter at korsgaard.com
Sun Nov 3 18:43:56 UTC 2019
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Fixes the following security issue:
> - CVE-2019-18408: archive_read_format_rar_read_data in
> archive_read_support_format_rar.c in libarchive before 3.4.0 has a
> use-after-free in a certain ARCHIVE_FAILED situation, related to
> Ppmd7_DecodeSymbol.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed to 2019.02.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list