UbuntuUpdates.org

Package "libarchive"

Name: libarchive

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Multi-format archive and compression library (development files)
  • Multi-format archive and compression library (shared library)

Latest version: 3.7.7-0ubuntu2.1
Release: plucky (25.04)
Level: updates
Repository: main

Links



Other versions of "libarchive" in Plucky

Repository Area Version
base main 3.7.7-0ubuntu2
base universe 3.7.7-0ubuntu2
security main 3.7.7-0ubuntu2.1
security universe 3.7.7-0ubuntu2.1
updates universe 3.7.7-0ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.7.7-0ubuntu2.1 2025-04-23 21:07:15 UTC

  libarchive (3.7.7-0ubuntu2.1) plucky-security; urgency=medium

  * SECURITY UPDATE: DoS via null pointer deref
    - debian/patches/CVE-2025-1632_25724.patch: check return code of
      archive_entry_pathname() in unzip/bsdunzip.c.
    - CVE-2025-1632
  * SECURITY UPDATE: DoS via crafted TAR archive
    - debian/patches/CVE-2025-1632_25724.patch: make sure ltime is valid in
      tar/util.c.
    - CVE-2025-25724

 -- Marc Deslauriers <email address hidden> Thu, 10 Apr 2025 13:23:10 -0400

CVE-2025-1632 A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. Th
CVE-2025-25724 list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspeci



About   -   Send Feedback to @ubuntu_updates