libarchive was updated to fix a directory traversal in the bsdcpio tool, which allowed attackers supplying crafted archives to overwrite files. (CVE-2015-2304)
Also, a integer overflow was fixed that could also overflow buffers. (CVE-2013-0211)
{ "binaries": [ { "libarchive13": "3.1.2-9.1" } ] }
{ "binaries": [ { "libarchive-devel": "3.1.2-9.1" } ] }