Vulnerability Bulletins

DSA-3574 libarchive - security update

   
Affected software Debian
 
Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered aheap-based buffer overflow vulnerability in the zip_read_mac_metadatafunction in libarchive, a multi-format archive and compression library,which may lead to the execution of arbitrary code if a user or automatedsystem is tricked into processing a specially crafted ZIP file.

More info:

https://www.debian.org/security/2016/dsa-3574