An update for libarchive is now available for openEuler-20.03-LTS-SP1
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2022-2126
Final
1.0
1.0
2022-12-02
Initial
2022-12-02
2022-12-02
openEuler SA Tool V1.0
2022-12-02
libarchive security update
An update for libarchive is now available for openEuler-20.03-LTS-SP1.
is an open-source BSD-licensed C programming library that provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution also includes bsdtar and bsdcpio, full-featured implementations of tar and cpio that use .
Security Fix(es):
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."(CVE-2022-36227)
An update for libarchive is now available for openEuler-20.03-LTS-SP1.
openEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
Critical
libarchive
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-2126
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-36227
https://nvd.nist.gov/vuln/detail/CVE-2022-36227
openEuler-20.03-LTS-SP1
libarchive-debuginfo-3.4.3-6.oe1.aarch64.rpm
libarchive-devel-3.4.3-6.oe1.aarch64.rpm
libarchive-debugsource-3.4.3-6.oe1.aarch64.rpm
libarchive-3.4.3-6.oe1.aarch64.rpm
libarchive-help-3.4.3-6.oe1.noarch.rpm
libarchive-3.4.3-6.oe1.src.rpm
libarchive-debuginfo-3.4.3-6.oe1.x86_64.rpm
libarchive-3.4.3-6.oe1.x86_64.rpm
libarchive-debugsource-3.4.3-6.oe1.x86_64.rpm
libarchive-devel-3.4.3-6.oe1.x86_64.rpm
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution.
2022-12-02
CVE-2022-36227
openEuler-20.03-LTS-SP1
Critical
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
libarchive security update
2022-12-02
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-2126