libarchive: bump to 3.7.7 fixing a lot of security issues
authorMatthias Franck <[email protected]>
Mon, 17 Mar 2025 09:08:10 +0000 (10:08 +0100)
committerTianling Shen <[email protected]>
Sun, 13 Apr 2025 08:43:29 +0000 (16:43 +0800)
commit39b1179bd663ca7d1a486df0372ed5d508156e22
treecb93dd0729cf7add697aa648405636ff930e5457
parentc5576299a0450435e77e67b2a364f9514465cc50
libarchive: bump to 3.7.7 fixing a lot of security issues

libarchive fixed a lot of security issues in the last few releases, listing only
notable changes,

libarchive 3.7.5:

   * rar4: protect copy_from_lzss_window_to_unp()  CVE-2024-20696
   * rar4: fix CVE-2024-26256

libarchive 3.7.6:

   * this release fixes a tar regression introduced in libarchive 3.7.5

libarchive 3.7.7:

   * gzip: prevent a hang when processing a malformed gzip inside a gzip (OSS-Fuzz)
   * tar: don't crash on truncated tar archives (OSS-Fuzz)
   * tar: fix two leaks in tar header parsing

Link: https://github.com/libarchive/libarchive/releases
Signed-off-by: Matthias Franck <[email protected]>
libs/libarchive/Makefile