Debian Package Tracker
Register | Log in
Subscribe

libarchive

Choose email to subscribe with

general
  • source: libarchive (main)
  • version: 3.6.0-1
  • maintainer: Peter Pentchev (DMD)
  • arch: any
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.2.2-2+deb9u2
  • o-o-sec: 3.2.2-2+deb9u3
  • o-o-bpo-sl: 3.4.0-2~bpo9+1
  • oldstable: 3.3.3-4+deb10u1
  • old-sec: 3.3.3-4+deb10u1
  • stable: 3.4.3-2
  • testing: 3.6.0-1
  • unstable: 3.6.0-1
versioned links
  • 3.2.2-2+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.2-2+deb9u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.3.3-4+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.0-2~bpo9+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libarchive-dev
  • libarchive-tools
  • libarchive13
action needed
A new upstream version is available: 3.6.1 high
A new upstream version 3.6.1 is available, you should consider packaging it.
Created: 2022-04-11 Last update: 2022-05-26 23:37
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2022-26280: Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
  • CVE-2022-28066: Libarchive v3.6.0 was discovered to contain a read memory access vulnerability via the function lzma_decode.
Created: 2021-07-20 Last update: 2022-05-12 21:30
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2022-26280: Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
  • CVE-2022-28066: Libarchive v3.6.0 was discovered to contain a read memory access vulnerability via the function lzma_decode.
Created: 2021-08-15 Last update: 2022-05-12 21:30
lintian reports 18 warnings normal
Lintian reports 18 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-09-21 Last update: 2022-01-01 04:32
4 low-priority security issues in buster low

There are 4 open security issues in buster.

4 issues left for the package maintainer to handle:
  • CVE-2019-19221: (needs triaging) In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
  • CVE-2021-23177: (needs triaging)
  • CVE-2021-31566: (needs triaging)
  • CVE-2021-36976: (needs triaging) libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-05-12 21:30
3 low-priority security issues in bullseye low

There are 3 open security issues in bullseye.

3 issues left for the package maintainer to handle:
  • CVE-2021-36976: (needs triaging) libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
  • CVE-2022-26280: (needs triaging) Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
  • CVE-2022-28066: (needs triaging) Libarchive v3.6.0 was discovered to contain a read memory access vulnerability via the function lzma_decode.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-08-14 Last update: 2022-05-12 21:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.6.0).
Created: 2022-05-11 Last update: 2022-05-11 23:24
news
[rss feed]
  • [2022-04-30] Accepted libarchive 3.2.2-2+deb9u3 (source all amd64) into oldoldstable (Thorsten Alteholz)
  • [2022-04-02] libarchive 3.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-30] Accepted libarchive 3.6.0-1 (source) into unstable (Peter Pentchev)
  • [2022-03-05] Accepted libarchive 3.4.3-2+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Peter Pentchev)
  • [2021-12-25] libarchive 3.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-22] Accepted libarchive 3.5.2-1 (source) into unstable (Peter Pentchev)
  • [2020-08-04] libarchive 3.4.3-2 MIGRATED to testing (Debian testing watch)
  • [2020-08-01] Accepted libarchive 3.4.3-2 (source) into unstable (Peter Pentchev)
  • [2020-06-06] libarchive 3.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-03] Accepted libarchive 3.4.3-1 (source) into unstable (Peter Pentchev)
  • [2020-05-12] libarchive 3.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-09] Accepted libarchive 3.4.2-1 (source) into unstable (Peter Pentchev)
  • [2020-03-20] Accepted libarchive 3.4.0-2~bpo9+1 (source amd64) into stretch-backports-sloppy->backports-policy, stretch-backports-sloppy (Debian FTP Masters) (signed by: Andreas Tille)
  • [2020-03-10] libarchive 3.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-03-07] Accepted libarchive 3.4.0-2 (source) into unstable (Peter Pentchev)
  • [2019-11-01] Accepted libarchive 3.3.3-4+deb10u1 (source all amd64) into proposed-updates->stable-new, proposed-updates (Thorsten Alteholz)
  • [2019-11-01] Accepted libarchive 3.2.2-2+deb9u2 (source all amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Thorsten Alteholz)
  • [2019-10-31] Accepted libarchive 3.2.2-2+deb9u2 (source all amd64) into oldstable->embargoed, oldstable (Thorsten Alteholz)
  • [2019-10-31] Accepted libarchive 3.3.3-4+deb10u1 (source all amd64) into stable->embargoed, stable (Thorsten Alteholz)
  • [2019-10-26] Accepted libarchive 3.1.2-11+deb8u8 (source amd64) into oldoldstable (Thorsten Alteholz)
  • [2019-09-23] libarchive 3.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2019-09-20] Accepted libarchive 3.4.0-1 (source) into unstable (Peter Pentchev)
  • [2019-02-08] libarchive 3.3.3-4 MIGRATED to testing (Debian testing watch)
  • [2019-02-07] Accepted libarchive 3.1.2-11+deb8u7 (source amd64) into oldstable (Antoine Beaupré)
  • [2019-02-06] Accepted libarchive 3.3.3-4 (source) into unstable (Peter Pentchev)
  • [2019-01-08] libarchive 3.3.3-3 MIGRATED to testing (Debian testing watch)
  • [2019-01-05] Accepted libarchive 3.3.3-3 (source) into unstable (Peter Pentchev)
  • [2018-12-30] Accepted libarchive 3.2.2-2+deb9u1 (source all amd64) into proposed-updates->stable-new, proposed-updates (Markus Koschany)
  • [2018-12-27] Accepted libarchive 3.2.2-2+deb9u1 (source all amd64) into stable->embargoed, stable (Markus Koschany)
  • [2018-12-24] libarchive 3.3.3-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 8
  • RC: 0
  • I&N: 5
  • M&W: 3
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 18)
  • buildd: logs, clang, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.6.0-1ubuntu1
  • 4 bugs
  • patches for 3.6.0-1ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing