Bug 8619

Summary: libarchive has open CVEs: CVE-2015-2304, CVE-2013-0211
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Elena Reshetova <elena.reshetova>
Component: coreAssignee: Ross Burton <ross.burton>
Status: RESOLVED OBSOLETE QA Contact:
Severity: normal    
Priority: Undecided CC: meta.mr.watcher, meta.watcher
Version: unspecified   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Comment 2 Ross Burton 2015-11-02 11:46:18 UTC
Also 2015-2304 is fixed in "0001-Add-ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS-option.patch".

I get why the 2015-2304 wasn't detected by whatever CVE scanning tool you are using, but I do wonder why 2012-0211 wasn't detected as it has the CVE name in the filename.
Comment 3 Elena Reshetova 2015-11-02 11:54:05 UTC
That's a good question. I will investigate why it wasn't detected. Now we have a first real case, so it helps.
Comment 4 Elena Reshetova 2015-11-03 08:46:02 UTC
Actually I checked this one and the fault is not on the tool side but on the reporter side (me :)). Tool correctly detected that there are two CVEs, but marked one as patched (2013 one), but since the difference in cve-check.tool reporting is only comma vs. space, I didn't notice it and reported both. 

Would it be possible to rename the patch for 2015 CVE also to somehow reflect that it fixes cve?
Comment 5 Ross Burton 2015-11-03 16:23:18 UTC
Yes, I'll send a rename patch for master.
Comment 6 Elena Reshetova 2015-11-03 18:36:09 UTC
Thank you very much!