[Buildroot] [PATCH-2019.02.x] package/libarchive: add upstream security fix for CVE-2019-18408

Peter Korsgaard peter at korsgaard.com
Sun Nov 3 18:43:56 UTC 2019


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issue:
 > - CVE-2019-18408: archive_read_format_rar_read_data in
 >   archive_read_support_format_rar.c in libarchive before 3.4.0 has a
 >   use-after-free in a certain ARCHIVE_FAILED situation, related to
 >   Ppmd7_DecodeSymbol.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2019.02.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list