QID 376502
QID 376502: Cygwin libarchive Package Multiple Security Vulnerabilities
Cygwin is a Linux-style operating environment for Microsoft Windows.
Multiple Security vulnerabilities were reported in libarchive.
Affected Versions:
Cygwin libarchive package prior to 3.5.3-1.
QID Detection Logic (authenticated):
The QID flags if it finds a vulnerable version of the libarchive package in installed file. The location of the file is determined by the key "HKLM\SOFTWARE\Cygwin\setup", value "rootdir". The file is present in the <rootdir>\etc\setup folder.
Successful exploitation of these vulnerabilities may affect confidentiality, integrity and availability.
Solution
Upgrade to Cygwin libarchive package to version 3.5.3-1 or later. For more information, please refer to the vendor advisory for affected Cygwin
Vendor References
- Cygwin Security Advisory -
cygwin.com/pipermail/cygwin-announce/2021-August/010180.html
CVEs related to QID 376502
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Cygwin Security Advisory |
|