1
0

Update submodules from pool/xar#1 and create patchinfo.20260622093221074059.93181000773252/_patchinfo

This commit is contained in:
2026-06-22 11:32:21 +02:00
parent ba99772faf
commit 426e775739
2 changed files with 31 additions and 1 deletions
@@ -0,0 +1,30 @@
<patchinfo>
<issue tracker="bnc" id="1108596">VUL-1: CVE-2018-17094: xar: An issue has been discovered in mackyle xar 1.6.1. There is a NULL pointerdereference in xar_unserialize in lib/archive.c.</issue>
<issue tracker="bnc" id="1108595">VUL-1: CVE-2018-17093: An issue has been discovered in mackyle xar 1.6.1. There is a NULL pointerdereference in xar_get_path in lib/util.c.</issue>
<issue tracker="bnc" id="1047875">VUL-0: CVE-2017-11124: xar: NULL pointer dereference in the xar_unserializefunction in archive.c.</issue>
<issue tracker="cve" id="2017-11124"/>
<issue tracker="cve" id="2018-17093"/>
<issue tracker="bnc" id="1047874">VUL-0: CVE-2017-11125: xar: NULL pointer dereference in the xar_get_pathfunction in util.c.</issue>
<issue tracker="cve" id="2018-17094"/>
<issue tracker="cve" id="2017-11125"/>
<packager>pluskalm</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for xar</summary>
<description>This update for xar fixes the following issues:
Changes in xar:
- Switch to the maintained Apple xar lineage (build 503, versioned
1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been
dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's
xar (apple-oss-distributions/xar). This resolves the long-standing
NULL-pointer dereferences in xar_get_path() and xar_unserialize()
when parsing malformed archives:
* CVE-2017-11124 (boo#1047875)
* CVE-2017-11125 (boo#1047874)
* CVE-2018-17093 (boo#1108595)
* CVE-2018-17094 (boo#1108596)
</description>
<package>xar</package>
</patchinfo>
+1 -1
Submodule xar updated: 29456e5ad3...92c5a9493f