An update for libarchive is now available for openEuler-20.03-LTS-SP3 Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2022-2123 Final 1.0 1.0 2022-12-02 Initial 2022-12-02 2022-12-02 openEuler SA Tool V1.0 2022-12-02 libarchive security update An update for libarchive is now available for openEuler-20.03-LTS-SP3. is an open-source BSD-licensed C programming library that provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution also includes bsdtar and bsdcpio, full-featured implementations of tar and cpio that use . Security Fix(es): In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."(CVE-2022-36227) An update for libarchive is now available for openEuler-20.03-LTS-SP3. openEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. Critical libarchive https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-2123 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-36227 https://nvd.nist.gov/vuln/detail/CVE-2022-36227 openEuler-20.03-LTS-SP3 libarchive-debuginfo-3.4.3-6.oe1.aarch64.rpm libarchive-devel-3.4.3-6.oe1.aarch64.rpm libarchive-debugsource-3.4.3-6.oe1.aarch64.rpm libarchive-3.4.3-6.oe1.aarch64.rpm libarchive-help-3.4.3-6.oe1.noarch.rpm libarchive-3.4.3-6.oe1.src.rpm libarchive-debuginfo-3.4.3-6.oe1.x86_64.rpm libarchive-3.4.3-6.oe1.x86_64.rpm libarchive-debugsource-3.4.3-6.oe1.x86_64.rpm libarchive-devel-3.4.3-6.oe1.x86_64.rpm In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution. 2022-12-02 CVE-2022-36227 openEuler-20.03-LTS-SP3 Critical 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H libarchive security update 2022-12-02 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-2123