{"id":"openSUSE-SU-2026:21153-1","summary":"Security update for xar","details":"This update for xar fixes the following issues:\n\nChanges in xar:\n\n- Switch to the maintained Apple xar lineage (build 503, versioned\n  1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been\n  dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's\n  xar (apple-oss-distributions/xar). This resolves the long-standing\n  NULL-pointer dereferences in xar_get_path() and xar_unserialize()\n  when parsing malformed archives:\n  * CVE-2017-11124 (boo#1047875)\n  * CVE-2017-11125 (boo#1047874)\n  * CVE-2018-17093 (boo#1108595)\n  * CVE-2018-17094 (boo#1108596)\n","modified":"2026-06-30T18:24:53.512889958Z","published":"2026-06-23T13:02:10Z","related":["CVE-2017-11124","CVE-2017-11125","CVE-2018-17093","CVE-2018-17094"],"upstream":["CVE-2017-11124","CVE-2017-11125","CVE-2018-17093","CVE-2018-17094"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1047874"},{"type":"REPORT","url":"https://bugzilla.suse.com/1047875"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-17093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-17094"}],"affected":[{"package":{"name":"xar","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/xar&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.0.503-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"xar":"1.8.0.0.503-bp160.1.1","libxar-devel":"1.8.0.0.503-bp160.1.1","libxar1":"1.8.0.0.503-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21153-1.json"}}],"schema_version":"1.7.5"}