Debian Security Advisory
DSA-3180-1 libarchive -- security update
- Date Reported:
- 05 Mar 2015
- Affected Packages:
- libarchive
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 778266.
In Mitre's CVE dictionary: CVE-2015-2304. - More information:
-
Alexander Cherepanov discovered that bsdcpio, an implementation of the
cpio
program part of the libarchive project, is susceptible to a directory traversal vulnerability via absolute paths.For the stable distribution (wheezy), this problem has been fixed in version 3.0.4-3+wheezy1.
For the upcoming stable distribution (jessie), this problem has been fixed in version 3.1.2-11.
For the unstable distribution (sid), this problem has been fixed in version 3.1.2-11.
We recommend that you upgrade your libarchive packages.