Package Release Info

libarchive-3.8.1-160000.2.2

Update Info: Base Release
Available in Package Hub : 16.0

platforms

AArch64
ppc64le
s390x
x86-64

subpackages

libarchive13-32bit

Change Logs

* Thu Jun 05 2025 andreas.stieger@gmx.de
- update to 3.8.1:
  * libarchive: fix FILE_skip regression
  * compress: Prevent call stack overflow
  * iso9660: always check archive_string_ensure return value
  * tar: Support negative time values with pax
  * tar: Reset accumulated header state after reading macOS metadata blob
  * tar: Keep block alignment after pax error
  * tar: Handle extra bytes after sparse entries
- includes changes from 3.8.0:
  * bsdtar: support --mtime and --clamp-mtime
  * 7-zip reader: improve self-extracting archive detection
  * xar: xmllite support for the XAR reader and writer
  * zip writer: added XZ, LZMA, ZSTD and BZIP2 support
  * zip writer: added LZMA + RISCV BCJ filter
  * rar: do not skip past EOF while reading (boo#1244159)
  * rar: fix double free with over 4 billion nodes (boo#1244160)
  * rar: fix heap-buffer-overflow (boo#1244161)
  * warc: prevent signed integer overflow (boo#1244162)
  * tar: fix overflow in build_ustar_entry (boo#1244163)
  * bsdtar: don't hardlink negative inode files together
  * gz: allow setting the original filename for gzip compressed files
  * lib: improve lseek handling
  * lib: support @-prefixed Unix epoch timestamps as date strings
  * rar: support large headers on 32 bit systems
  * tar reader: Improve LFS support on 32 bit systems
- drop lib-suffix.patch, different implementation upstream
- spec file clean-up, removing currently unused -static
* Sat Apr 05 2025 andreas.stieger@gmx.de
- Update to 3.7.9:
  * fix regression regarding GNU sparse entries
* Sun Mar 23 2025 andreas.stieger@gmx.de
- Update to 3.7.8:
  * 7zip reader: add SPARC and POWERPC filter support for non-LZMA compressors
  * tar reader: Ignore ustar size when pax size is present
  * tar writer: Fix bug when -s/a/b/ used more than once with b flag
  * libarchive: Handle ARCHIVE_FILTER_LZOP in archive_read_append_filter
  * libarchive: Adding missing seeker function to archive_read_open_FILE()
- inludes the previously patched security fixes, dropping:
  CVE-2025-1632.patch, CVE-2025-25724.patch, CVE-2024-57970.patch
* Tue Mar 11 2025 marius.grossu@suse.com
- Fix CVE-2025-1632, null pointer dereference in bsdunzip.c
  (CVE-2025-1632, bsc#1237606)
  * CVE-2025-1632.patch
- Fix CVE-2025-25724, Buffer Overflow vulnerability in libarchive
  (CVE-2025-25724, bsc#1238610)
  * CVE-2025-25724.patch
* Tue Feb 25 2025 antonio.teixeira@suse.com
- Fix CVE-2024-57970, heap-based buffer over-read in header_gnu_longlink
  because it mishandles truncation (CVE-2024-57970, bsc#1237233)
  * CVE-2024-57970.patch
* Thu Oct 17 2024 antonio.teixeira@suse.com
- Update to 3.7.7:
  * gzip: prevent a hang when processing a malformed gzip inside a gzip
  * tar: don't crash on truncated tar archives
  * tar: fix two leaks in tar header parsing
  * 7-zip: read/write symlink paths as UTF-8
  * cpio: exit with an error code if an entry could not be extracted
  * rar5: report encrypted entries
  * tar: fix truncation of entry pathnames in specific archives
* Fri Sep 27 2024 antonio.teixeira@suse.com
- Update to 3.7.6:
  * tar: clean up linkpath between entries
  * tar: fix memory leaks when processing symlinks or parsing pax headers
  * iso: be more cautious about parsing ISO-9660 timestamps
- Version 3.7.5 changes:
  * fix multiple vulnerabilities identified by SAST
  * cpio: ignore out-of-range gid/uid/size/ino and harden AFIO parsing
  * lzop: prevent integer overflow
  * rar4: protect copy_from_lzss_window_to_unp() (CVE-2024-20696, bsc#1225971)
  * rar4: fix CVE-2024-26256 (CVE-2024-26256, bsc#1225972)
  * rar4: fix OOB in delta and audio filter
  * rar4: fix out of boundary access with large files
  * rar4: add boundary checks to rgb filter
  * rar4: fix OOB access with unicode filenames
  * rar5: clear 'data ready' cache on window buffer reallocs
  * rpm: calculate huge header sizes correctly
  * unzip: unify EOF handling
  * util: fix out of boundary access in mktemp functions
  * uu: stop processing if lines are too long
  * 7zip: fix issue when skipping first file in 7zip archive that is a multiple
    of 65536 bytes
  * ar: fix archive entries having no type
  * lha: do not allow negative file sizes
  * lha: fix integer truncation on 32-bit systems
  * shar: check strdup return value
  * rar5: don't try to read rediculously long names
  * xar: fix another infinite loop and expat error handling
  * many Windows fixes, cleanups and improvements
- Drop fix-soversion.patch, fix-bsdunzip-test.patch
  * Fixed upstream
* Thu Jun 20 2024 antonio.teixeira@suse.com
- Update lib-suffix.patch
  * Add LIB_SUFFIX to libdir path in the pkg-config file
* Wed May 22 2024 danilo.spinella@suse.com
- Fix bsdunzip test failing due to a locale issue
  * fix-bsdunzip-test.patch
* Tue Apr 30 2024 danilo.spinella@suse.com
- Update to 3.7.4:
  * rar: Fix OOB in rar e8 filter (CVE-2024-26256, bsc#1222911)
  * zip: Fix out of boundary access
  * 7zip: Limit amount of properties
  * bsdtar: Fix error handling around strtol() usages
  * passphrase: Improve newline handling on Windows
  * passphrase: Never allow empty passwords
  * rar: Fix "File CRC Error" when extracting specific rar4 archives
  * xar: Avoid infinite link loop
  * zip: Update AppleDouble support for directories
  * zstd: Implement core detection
- Update to 3.7.3:
  * PCRE2 support
  * add trailing letter b to bsdtar(1) substitute pattern
  * add support for long options "--group" and "--owner" to tar(1)
  * Fix possible vulnerability in tar error reporting introduced in f27c173
  * ISO9660: preserve the natural order of links
  * rar5: fix decoding unicode filenames on Windows
  * rar5: fix infinite loop if during rar5 decompression the last block produced no data
  * xz filter: fix incorrect eof at the end of an lzip member
  * zip: fix end-of-data marker processing when decompressing zip archives
  * multiple bsdunzip(1) fixes
  * filetime truncation fix on Windows
- Fix rpmlint warning about summary being too long