https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2304 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0211
2013-0211 is in git already: http://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/recipes-extended/libarchive/libarchive/libarchive-CVE-2013-0211.patch
Also 2015-2304 is fixed in "0001-Add-ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS-option.patch". I get why the 2015-2304 wasn't detected by whatever CVE scanning tool you are using, but I do wonder why 2012-0211 wasn't detected as it has the CVE name in the filename.
That's a good question. I will investigate why it wasn't detected. Now we have a first real case, so it helps.
Actually I checked this one and the fault is not on the tool side but on the reporter side (me :)). Tool correctly detected that there are two CVEs, but marked one as patched (2013 one), but since the difference in cve-check.tool reporting is only comma vs. space, I didn't notice it and reported both. Would it be possible to rename the patch for 2015 CVE also to somehow reflect that it fixes cve?
Yes, I'll send a rename patch for master.
Thank you very much!