diff --git a/libarchive-3.6.0.tar.xz b/libarchive-3.6.0.tar.xz deleted file mode 100644 index 36abb73..0000000 --- a/libarchive-3.6.0.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:df283917799cb88659a5b33c0a598f04352d61936abcd8a48fe7b64e74950de7 -size 6400620 diff --git a/libarchive-3.6.0.tar.xz.asc b/libarchive-3.6.0.tar.xz.asc deleted file mode 100644 index 9754daf..0000000 --- a/libarchive-3.6.0.tar.xz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEEpaRbEq2S2WS4nu4t7FYMgc7CJ24FAmIDuEYACgkQ7FYMgc7C -J27jzxAAgljw3UAiatKlnwkMSqYhLmWDOPC21cDvlxvrcBOcqisDpnQXatyd53g/ -MJ2hx73+iL6kI6J0KxnJ8Y31P3qiBapiEZuJ+7b0QRPcp/H9zmPZbjcglhqRmx4A -53j8JaoD4BbwPg64rpU3yOqlCTVR3AXEr7/c/uZh2X3gPEWJm3Nq+8E+kp/aqjg/ -82cFAIs1M7C/f8KrsJdM075QjhzoSLV0ul7LiUuG3abY05+pjfgROv+pxZPkgoEM -gWsUKijy7n4ikYN/rbCl/vUaguy3+CE6QwmhqpbmbKscpodczVkaBQVvc2tMA1vM -1sRiwE+sfyyBxeIvmi3cdFNbqHS4Zjof/n/S2/7jbmUHrJNzOQaZSUocpCRKX10W -iafAna3ZTsxh6g2UEhrKVovKq3Sbt82a5NPPc40rNsbVOcmyp6cIWc9pZEDGrVt+ -dNLg2F6bo7KWIXCn0il7/f/brB3rl6W18K5SWkjsll6IOAJgjliaeW6StfHMe9my -zqVrtQuCMr5iaoLH2LHfDF5Lx1y26lIwVb4/+mSg+5zrdm+QnsYdFqleF6oVPu6d -RdxckxD1fSyuLgvYU8Nu+TyaaGDJenbaNnwkbLGNzkehlPs3q46tzoNBpEQv1blT -dYkWe/XtNuTWU/bTFtgrOfpYCObdIbNCNMCafezQKgOK7e+nUUs= -=XkqI ------END PGP SIGNATURE----- diff --git a/libarchive-3.6.1.tar.xz b/libarchive-3.6.1.tar.xz new file mode 100644 index 0000000..a71b67f --- /dev/null +++ b/libarchive-3.6.1.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:5a411aceb978f43e626f0c2d1812ddd8807b645ed892453acabd532376c148e6 +size 5241148 diff --git a/libarchive-3.6.1.tar.xz.asc b/libarchive-3.6.1.tar.xz.asc new file mode 100644 index 0000000..c0c1a01 --- /dev/null +++ b/libarchive-3.6.1.tar.xz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEEpaRbEq2S2WS4nu4t7FYMgc7CJ24FAmJQLM4ACgkQ7FYMgc7C +J25kgw/+Oge7Y9DZi/TgZpPOumYcboKnrGcG1ML1bemMS7HTWhOfMAY+w3bIpQ9F +Fyj3dm/eQU5mw0JyoefqFG6JXSq0nEBof2xijApLxXBijrR4PCC8f1qr0oOb2wAt +gvgdk02NiWMYX+tNTR2jzR5qeg+hl/sNPDxgNAGuVArayG11mcEsU3LuEpB2jPK0 +vUzLu5AecA7fjoUU8gRiGWT4EbQN3zHIfjA9Lzi+DSTYhL+BRg6Kt83HsqL6wiEu +XhsbusdwBpkCsDHJJsGGTU1//DZi5iIrS4DNDYJYSdcHkKutDfE1vBHK18HpmDZc +MMeGUGHauNYE7oiMs+e26cKxr2W+Ghuu3ID12dHLAuIQdboVaGHOaksT1wI3dC1F +VqJJOiqAAtiVjUWi6vz+y/gHhog553uF4V6kOAHkZ4Udb2lD/D6XMAsotFvP4rHS +M6ArRhcuimKalnk9cRgIS2LCISAmQIUEahUTDEL2DOZW35Lz3cGeXnhY19sLpTxC +1TFHnmEtTlg/NGlDy1iHbSQfto/OdM7q5OzWT195KRw4cYETkig9q3Y1kijogMYs +snP07Lo7TiwGAcgX1XYu+vUwZdPd3nl+Z2FKSxoCnjCsfxbuxkbgjkFqi/5os78p +2U/kA/gykq37g9ZRs/ywbVe9MDCYyfvOGNZ906BMypKFmQqLy1U= +=wTQm +-----END PGP SIGNATURE----- diff --git a/libarchive.changes b/libarchive.changes index 5e5147d..ca2a9d0 100644 --- a/libarchive.changes +++ b/libarchive.changes @@ -1,3 +1,15 @@ +------------------------------------------------------------------- +Fri Apr 8 17:01:05 UTC 2022 - Dirk Müller + +- update to 3.6.1: + * 7zip reader: fix PPMD read beyond boundary (#1671) + * ZIP reader: fix possible out of bounds read (OSS-Fuzz 38766 #1672) + * ISO reader: fix possible heap buffer overflow in read_children() (OSS-Fuzz 38764, #1685) + * RARv4 redaer: fix multiple issues in RARv4 filter code (introduced in libarchive 3.6.0) + * fix heap use after free in archive_read_format_rar_read_data() (OSS-Fuzz 44547, 52efa50) + * fix null dereference in read_data_compressed() (OSS-Fuzz 44843, 1271f77) + * fix heap user after free in run_filters() (OSS-Fuzz 46279, #1715) + ------------------------------------------------------------------- Thu Feb 24 19:18:32 UTC 2022 - Ferdinand Thiessen diff --git a/libarchive.spec b/libarchive.spec index 95b1eab..b7d5029 100644 --- a/libarchive.spec +++ b/libarchive.spec @@ -30,14 +30,14 @@ %bcond_without ext2fs %endif Name: libarchive -Version: 3.6.0 +Version: 3.6.1 Release: 0 Summary: Utility and C library to create and read several different streaming archive formats License: BSD-2-Clause Group: Productivity/Archiving/Compression URL: https://www.libarchive.org/ -Source0: https://www.libarchive.org/downloads/libarchive-%{version}.tar.xz -Source1: https://www.libarchive.org/downloads/libarchive-%{version}.tar.xz.asc +Source0: https://github.com/libarchive/libarchive/releases/download/v%{version}/libarchive-%{version}.tar.xz +Source1: https://github.com/libarchive/libarchive/releases/download/v%{version}/libarchive-%{version}.tar.xz.asc Source2: libarchive.keyring Source1000: baselibs.conf Patch1: lib-suffix.patch