MGASA-2021-0430

Source
https://advisories.mageia.org/MGASA-2021-0430.html
Import Source
https://advisories.mageia.org/MGASA-2021-0430.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0430
Published
2021-09-23T04:49:29Z
Modified
2026-04-16T04:24:35.101765Z
Summary
Updated libarchive packages fix security vulnerability
Details

Fix handling of symbolic link ACLs on Linux.

Never follow symlinks when setting file flags on Linux.

Do not follow symlinks when processing the fixup list.

References
Credits

Affected packages

Mageia:8 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/mageia/libarchive?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.2-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0430.json"