HomeFreeBSD

MFH r324148:

Description

MFH r324148:
Sync libarchive with vendor.

Relevant vendor changes:

PR #905: Support for Zstandard read and write filters
PR #922: Avoid overflow when reading corrupt cpio archive
Issue #935: heap-based buffer overflow in xml_data (CVE-2017-14166)
OSS-Fuzz 2936: Place a limit on the mtree line length
OSS-Fuzz 2394: Ensure that the ZIP AES extension header is large enough
OSS-Fuzz 573: Read off-by-one error in RAR archives (CVE-2017-14502)

Security: CVE-2017-14166, CVE-2017-14502

Details

Provenance
mmAuthored on
Parents
rS324417: MFH r324148:
Branches
Unknown
Tags
Unknown