Debian Security Advisory

DSA-3677-1 libarchive -- security update

Date Reported:
25 Sep 2016
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 837714.
In Mitre's CVE dictionary: CVE-2016-5418, CVE-2016-6250, CVE-2016-7166.
More information:

Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library, which may lead to denial of service (memory consumption and application crash), bypass of sandboxing restrictions and overwrite arbitrary files with arbitrary data from an archive, or the execution of arbitrary code.

For the stable distribution (jessie), these problems have been fixed in version 3.1.2-11+deb8u3.

We recommend that you upgrade your libarchive packages.