Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 527218) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,38 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + libarchive -- SIGSEGV or possibly unspecified other impact + + + libarchive + 3.4.2,1 + + + + +

MITRE Corporation reports:

+
+

+ archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to + unpack a RAR5 file with an invalid or corrupted header (such as a header + size of zero), leading to a SIGSEGV or possibly unspecified other impact. +

+
+ +
+ + CVE-2020-9308 + https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20459 + https://github.com/libarchive/libarchive/pull/1326 + https://github.com/libarchive/libarchive/pull/1326/commits/94821008d6eea81e315c5881cdf739202961040a + + + 2020-02-20 + 2020-02-27 + +
+ LPE and RCE in OpenSMTPD's default install