Path to this page:
Subject: CVS import: pkgsrc/archivers/libarchive/files
From: Adam Ciarcinski
Date: 2024-09-15 08:46:23
Message id: 20240915064623.7E288FC74@cvs.NetBSD.org
Log Message:
libarchive: imported version 3.7.5
Libarchive 3.7.5
Security fixes:
fix multiple vulnerabilities identified by SAST
cpio: ignore out-of-range gid/uid/size/ino and harden AFIO parsing
lzop: prevent integer overflow
rar4: protect copy_from_lzss_window_to_unp()
rar4: fix CVE-2024-26256
rar4: fix OOB in delta and audio filter
rar4: fix out of boundary access with large files
rar4: add boundary checks to rgb filter
rar4: fix OOB access with unicode filenames
rar5: clear 'data ready' cache on window buffer reallocs
rpm: calculate huge header sizes correctly
unzip: unify EOF handling
util: fix out of boundary access in mktemp functions
uu: stop processing if lines are too long
Important bugfixes:
7zip: fix issue when skipping first file in 7zip archive that is a multiple of \
65536 bytes
ar: fix archive entries having no type
lha: do not allow negative file sizes
lha: fix integer truncation on 32-bit systems
shar: check strdup return value
rar5: don't try to read rediculously long names
xar: fix another infinite loop and expat error handling
many Windows fixes, cleanups and improvements
Files: