libarchive security vulnerabiity, FreeBSD affected?

Well, a quick check says to me that the issues are not those fixed by the 2 recent security patches:

Here are the vulnerability IDs in the Talos blog post:

I'd guess that until someone confirms the specific cases for FreeBSD, you should probably assume that the vulnerabilities do exist here.

Edit: It looks like the fix has already been added to base/head/contrib/libarchive in revision 302075, and is awaiting MFC. My personal guess is that you will probably see it land in supported versions of FreeBSD very soon, as long as nothing breaks when they try to merge it.
 
Back
Top