Debian Package Tracker
Register | Log in
Subscribe

libarchive

Choose email to subscribe with

general
  • source: libarchive (main)
  • version: 3.6.2-1
  • maintainer: Peter Pentchev (DMD)
  • arch: any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.3.3-4+deb10u1
  • o-o-sec: 3.3.3-4+deb10u3
  • oldstable: 3.4.3-2+deb11u1
  • stable: 3.6.2-1
  • testing: 3.6.2-1
  • unstable: 3.6.2-1
versioned links
  • 3.3.3-4+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.3.3-4+deb10u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.3-2+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libarchive-dev
  • libarchive-tools
  • libarchive13 (2 bugs: 0, 2, 0, 0)
action needed
A new upstream version is available: 3.7.2 high
A new upstream version 3.7.2 is available, you should consider packaging it.
Created: 2023-08-02 Last update: 2023-09-22 02:04
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-30571: Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.
Created: 2023-05-30 Last update: 2023-06-11 06:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2023-30571: Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.
Created: 2023-06-11 Last update: 2023-06-11 06:30
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2023-09-13 Last update: 2023-09-22 06:02
4 low-priority security issues in bullseye low

There are 4 open security issues in bullseye.

4 issues left for the package maintainer to handle:
  • CVE-2021-36976: (needs triaging) libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
  • CVE-2022-26280: (needs triaging) Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
  • CVE-2022-36227: (needs triaging) In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
  • CVE-2023-30571: (needs triaging) Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

You can find information about how to handle these issues in the security team's documentation.

Created: 2022-07-04 Last update: 2023-06-11 06:30
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-30571: (needs triaging) Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-06-10 Last update: 2023-06-11 06:30
news
[rss feed]
  • [2023-01-30] Accepted libarchive 3.3.3-4+deb10u3 (source) into oldstable (Thorsten Alteholz)
  • [2022-12-27] libarchive 3.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-27] libarchive 3.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-24] Accepted libarchive 3.6.2-1 (source) into unstable (Peter Pentchev)
  • [2022-11-22] Accepted libarchive 3.3.3-4+deb10u2 (source) into oldstable (Sylvain Beucler)
  • [2022-04-30] Accepted libarchive 3.2.2-2+deb9u3 (source all amd64) into oldoldstable (Thorsten Alteholz)
  • [2022-04-02] libarchive 3.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-30] Accepted libarchive 3.6.0-1 (source) into unstable (Peter Pentchev)
  • [2022-03-05] Accepted libarchive 3.4.3-2+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Peter Pentchev)
  • [2021-12-25] libarchive 3.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-22] Accepted libarchive 3.5.2-1 (source) into unstable (Peter Pentchev)
  • [2020-08-04] libarchive 3.4.3-2 MIGRATED to testing (Debian testing watch)
  • [2020-08-01] Accepted libarchive 3.4.3-2 (source) into unstable (Peter Pentchev)
  • [2020-06-06] libarchive 3.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-03] Accepted libarchive 3.4.3-1 (source) into unstable (Peter Pentchev)
  • [2020-05-12] libarchive 3.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-09] Accepted libarchive 3.4.2-1 (source) into unstable (Peter Pentchev)
  • [2020-03-20] Accepted libarchive 3.4.0-2~bpo9+1 (source amd64) into stretch-backports-sloppy->backports-policy, stretch-backports-sloppy (Debian FTP Masters) (signed by: Andreas Tille)
  • [2020-03-10] libarchive 3.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-03-07] Accepted libarchive 3.4.0-2 (source) into unstable (Peter Pentchev)
  • [2019-11-01] Accepted libarchive 3.3.3-4+deb10u1 (source all amd64) into proposed-updates->stable-new, proposed-updates (Thorsten Alteholz)
  • [2019-11-01] Accepted libarchive 3.2.2-2+deb9u2 (source all amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Thorsten Alteholz)
  • [2019-10-31] Accepted libarchive 3.2.2-2+deb9u2 (source all amd64) into oldstable->embargoed, oldstable (Thorsten Alteholz)
  • [2019-10-31] Accepted libarchive 3.3.3-4+deb10u1 (source all amd64) into stable->embargoed, stable (Thorsten Alteholz)
  • [2019-10-26] Accepted libarchive 3.1.2-11+deb8u8 (source amd64) into oldoldstable (Thorsten Alteholz)
  • [2019-09-23] libarchive 3.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2019-09-20] Accepted libarchive 3.4.0-1 (source) into unstable (Peter Pentchev)
  • [2019-02-08] libarchive 3.3.3-4 MIGRATED to testing (Debian testing watch)
  • [2019-02-07] Accepted libarchive 3.1.2-11+deb8u7 (source amd64) into oldstable (Antoine Beaupré)
  • [2019-02-06] Accepted libarchive 3.3.3-4 (source) into unstable (Peter Pentchev)
  • 1
  • 2
bugs [bug history graph]
  • all: 10
  • RC: 0
  • I&N: 7
  • M&W: 3
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.6.2-1ubuntu1
  • 3 bugs
  • patches for 3.6.2-1ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing