ELA-1233-1 libarchive security update

out-of-bounds write

2024-11-11
Packagelibarchive
Version3.1.2-11+deb8u12 (jessie), 3.2.2-2+deb9u5 (stretch), 3.3.3-4+deb10u4 (buster)
Related CVEs CVE-2024-20696


RAR reader out-of-bounds write has been fixed in libarchive, a multi-format archive and compression library.



For Debian 10 buster, these problems have been fixed in version 3.3.3-4+deb10u4.

For Debian 8 jessie, these problems have been fixed in version 3.1.2-11+deb8u12.

For Debian 9 stretch, these problems have been fixed in version 3.2.2-2+deb9u5.

We recommend that you upgrade your libarchive packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.