{"id":"MGASA-2021-0430","summary":"Updated libarchive packages fix security vulnerability","details":"Fix handling of symbolic link ACLs on Linux.\n\nNever follow symlinks when setting file flags on Linux.\n\nDo not follow symlinks when processing the fixup list.\n","modified":"2026-04-16T04:24:35.101765Z","published":"2021-09-23T04:49:29Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0430.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29431"},{"type":"WEB","url":"https://github.com/libarchive/libarchive/releases/tag/v3.5.2"}],"affected":[{"package":{"name":"libarchive","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/libarchive?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.2-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0430.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}