diff options
| author | Martin Matuska <mm@FreeBSD.org> | 2023-09-07 15:18:12 +0000 |
|---|---|---|
| committer | Martin Matuska <mm@FreeBSD.org> | 2023-09-11 07:05:29 +0000 |
| commit | 5ed7eb0d97ba4436218e810f61bd059acba984c2 (patch) | |
| tree | 30ccbfa290ad42bfecf8b92ccd4955c93f46372d /libexec | |
| parent | e59d10aff6edc088850be553252020230a560514 (diff) | |
libarchive: merge security fix from vendor branchstable/11
This commit fixes a couple of security vulnerabilities in the PAX writer:
1. Heap overflow in url_encode() in archive_write_set_format_pax.c
2. NULL dereference in archive_write_pax_header_xattrs()
3. Another NULL dereference in archive_write_pax_header_xattrs()
4. NULL dereference in archive_write_pax_header_xattr()
Security: No known reference yet
Obtained from: https://github.com/libarchive/libarchive/commit/1b4e0d0f9
MFC after: 3 days
(cherry picked from commit f10f65999fe56e92f00b5bc5d27ac342cfea5364)
Diffstat (limited to 'libexec')
0 files changed, 0 insertions, 0 deletions
