PT-2017-3768 · Libarchive+4 · Libarchive+4

Carnilo

·

Publicado

2017-09-16

·

Atualizado

2021-08-17

·

CVE-2017-14503

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libarchive version 3.3.2
Description: The issue is related to an out-of-bounds read within the lha read data none() function in archive read support format lha.c when extracting a specially crafted lha archive. This is connected to lha crc16. Exploitation of the issue may allow a remote attacker to gain unauthorized access to information using a specially created lha archive.
Recommendations: For libarchive version 3.3.2, as a temporary workaround, consider disabling the lha read data none() function until a patch is available. Restrict access to the archive read support format lha.c module to minimize the risk of exploitation. Avoid using the lha crc16 variable in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00928
CESA-2019_2298
CESA-2019_3698
CVE-2017-14503
DLA-1600-1
DSA-4360-1
MGASA-2018-0361
OPENSUSE-SU-2018_3690-1
OPENSUSE-SU-2018_3717-1
RHSA-2019:2298
RHSA-2019:3698
RHSA-2019_2298
RHSA-2019_3698
SUSE-RU-2021:2757-1
SUSE-SU-2018:3571-1
SUSE-SU-2018:3640-1
SUSE-SU-2018:3640-2
USN-3736-1

Produtos afetados

Centos
Red Hat
Suse
Ubuntu
Libarchive