Oval Definition:oval:org.opensuse.security:def:60414
Revision Date:2021-11-17Version:1
Title:Security update for libarchive (Moderate)
Description:

This update for libarchive fixes the following issues:

- CVE-2019-19221: Fixed out-of-bounds read caused by incorrect mbrtowc or mbtowc call (bsc#1157569)

- backporting symlink security fixes from 3.5.2: - extracting with ACLs modifies ACLs of target (bsc#1192425) - modifies file flags of target (bsc#1192426) - avoid follow on fixup entries (bsc#1192427)
Family:unixClass:patch
Status:Reference(s):1009254
1012215
1039567
1055123
1059812
1061832
1070724
1071853
1087200
1091072
1093536
1094462
1107874
1109465
1109663
1109845
1109847
1117473
1122292
1122299
1123482
1124525
1133810
1135715
1138459
1140868
1141780
1141782
1141783
1141785
1141787
1141789
1145665
1147021
1148931
1149323
1154862
1157569
1168874
1174922
1174923
1192425
1192426
1192427
CVE-2009-0945
CVE-2011-3193
CVE-2011-3922
CVE-2012-4929
CVE-2012-6093
CVE-2013-0254
CVE-2013-4549
CVE-2013-7038
CVE-2013-7039
CVE-2014-0190
CVE-2014-2653
CVE-2014-9622
CVE-2015-0295
CVE-2015-1858
CVE-2015-1859
CVE-2015-1860
CVE-2015-5352
CVE-2015-5600
CVE-2015-6563
CVE-2015-6564
CVE-2015-7236
CVE-2015-8325
CVE-2016-0777
CVE-2016-0778
CVE-2016-10009
CVE-2016-10010
CVE-2016-10011
CVE-2016-10012
CVE-2016-1908
CVE-2016-3115
CVE-2016-6210
CVE-2016-6515
CVE-2016-8858
CVE-2017-12173
CVE-2017-14160
CVE-2017-15108
CVE-2017-8779
CVE-2018-1000802
CVE-2018-10393
CVE-2018-10811
CVE-2018-11212
CVE-2018-14647
CVE-2018-16151
CVE-2018-16152
CVE-2018-17540
CVE-2018-5388
CVE-2019-10160
CVE-2019-11709
CVE-2019-11710
CVE-2019-11711
CVE-2019-11712
CVE-2019-11713
CVE-2019-11714
CVE-2019-11715
CVE-2019-11716
CVE-2019-11717
CVE-2019-11718
CVE-2019-11719
CVE-2019-11720
CVE-2019-11721
CVE-2019-11723
CVE-2019-11724
CVE-2019-11725
CVE-2019-11727
CVE-2019-11728
CVE-2019-11729
CVE-2019-11730
CVE-2019-11733
CVE-2019-11735
CVE-2019-11736
CVE-2019-11738
CVE-2019-11740
CVE-2019-11742
CVE-2019-11743
CVE-2019-11744
CVE-2019-11746
CVE-2019-11747
CVE-2019-11748
CVE-2019-11749
CVE-2019-11750
CVE-2019-11751
CVE-2019-11752
CVE-2019-11753
CVE-2019-11771
CVE-2019-11772
CVE-2019-11775
CVE-2019-17498
CVE-2019-19221
CVE-2019-2449
CVE-2019-2762
CVE-2019-2766
CVE-2019-2769
CVE-2019-2786
CVE-2019-2816
CVE-2019-4473
CVE-2019-7317
CVE-2019-8595
CVE-2019-8607
CVE-2019-8615
CVE-2019-8644
CVE-2019-8649
CVE-2019-8658
CVE-2019-8666
CVE-2019-8669
CVE-2019-8671
CVE-2019-8672
CVE-2019-8673
CVE-2019-8676
CVE-2019-8677
CVE-2019-8678
CVE-2019-8679
CVE-2019-8680
CVE-2019-8681
CVE-2019-8683
CVE-2019-8684
CVE-2019-8686
CVE-2019-8687
CVE-2019-8688
CVE-2019-8689
CVE-2019-8690
CVE-2019-9811
CVE-2019-9812
CVE-2020-12673
CVE-2020-12674
CVE-2020-6821
CVE-2020-6822
CVE-2020-6825
CVE-2020-6827
CVE-2020-6828
SUSE-SU-2017:2937-1
SUSE-SU-2018:0372-1
SUSE-SU-2018:1324-1
SUSE-SU-2019:2053-2
SUSE-SU-2019:2620-1
SUSE-SU-2019:2936-1
SUSE-SU-2019:3266-1
SUSE-SU-2020:0978-1
SUSE-SU-2020:2274-1
SUSE-SU-2021:3722-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • cargo-1.36.0-lp150.16 is installed
  • OR cargo-doc-1.36.0-lp150.16 is installed
  • OR clippy-1.36.0-lp150.16 is installed
  • OR rls-1.36.0-lp150.16 is installed
  • OR rust-1.36.0-lp150.16 is installed
  • OR rust-analysis-1.36.0-lp150.16 is installed
  • OR rust-cbindgen-0.8.7-lp150.2 is installed
  • OR rust-doc-1.36.0-lp150.16 is installed
  • OR rust-gdb-1.36.0-lp150.16 is installed
  • OR rust-src-1.36.0-lp150.16 is installed
  • OR rust-std-static-1.36.0-lp150.16 is installed
  • OR rustfmt-1.36.0-lp150.16 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • exempi-2.4.5-lp151.3.3 is installed
  • OR exempi-tools-2.4.5-lp151.3.3 is installed
  • OR libexempi-devel-2.4.5-lp151.3.3 is installed
  • OR libexempi3-2.4.5-lp151.3.3 is installed
  • OR libexempi3-32bit-2.4.5-lp151.3.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libraw-0.18.9-lp152.5.3 is installed
  • OR libraw-devel-0.18.9-lp152.5.3 is installed
  • OR libraw-devel-static-0.18.9-lp152.5.3 is installed
  • OR libraw-tools-0.18.9-lp152.5.3 is installed
  • OR libraw16-0.18.9-lp152.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND libmicrohttpd10-0.9.30-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • MozillaFirefox-68.1.0-109.89 is installed
  • OR MozillaFirefox-branding-SLE-68-32.8 is installed
  • OR MozillaFirefox-translations-common-68.1.0-109.89 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.24.4-2.47 is installed
  • OR libwebkit2gtk-4_0-37-2.24.4-2.47 is installed
  • OR libwebkit2gtk3-lang-2.24.4-2.47 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.24.4-2.47 is installed
  • OR typelib-1_0-WebKit2-4_0-2.24.4-2.47 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.24.4-2.47 is installed
  • OR webkit2gtk3-2.24.4-2.47 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • strongswan-5.1.3-26.13 is installed
  • OR strongswan-doc-5.1.3-26.13 is installed
  • OR strongswan-hmac-5.1.3-26.13 is installed
  • OR strongswan-ipsec-5.1.3-26.13 is installed
  • OR strongswan-libs0-5.1.3-26.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gnome-shell-search-provider-nautilus-3.20.3-23.6 is installed
  • OR libnautilus-extension1-3.20.3-23.6 is installed
  • OR nautilus-3.20.3-23.6 is installed
  • OR nautilus-lang-3.20.3-23.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND python-ipaddress-1.0.18-3.13 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND libarchive13-3.3.3-32.5.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND libarchive13-3.3.3-32.5.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.14 is installed
  • OR libssh2-1-32bit-1.4.3-20.14 is installed
  • OR libssh2_org-1.4.3-20.14 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-requests-2.20.1-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.6-25.29 is installed
  • OR python3-3.4.6-25.29 is installed
  • OR python3-base-3.4.6-25.29 is installed
  • OR python3-curses-3.4.6-25.29 is installed
  • BACK