PT-2018-2542 · Libarchive+3 · Libarchive+3

Publicado

2018-09-28

·

Atualizado

2024-06-15

·

CVE-2018-1000880

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions 3.2.0 and later
Description The issue is related to improper input validation in the WARC parser, specifically in the warc read() function within archive read support format warc.c. This can lead to a denial of service (DoS) due to quasi-infinite runtime and disk usage from a tiny, specially crafted WARC file. The attack is exploitable if the victim opens such a crafted file, potentially allowing a remote attacker to cause a service disruption.
Recommendations For libarchive versions 3.2.0 and later, consider disabling the WARC parsing functionality until a patch is available to prevent exploitation. Restrict access to the warc read() function in archive read support format warc.c to minimize the risk of denial of service attacks. Avoid opening untrusted or specially crafted WARC files with the affected libarchive versions.

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2522
ALT-PU-2019-3125
BDU:2019-00927
CVE-2018-1000880
DSA-4360-1
MGASA-2019-0030
OPENSUSE-SU-2019:1196-1
OPENSUSE-SU-2019_1196-1
OPENSUSE-SU-2024:10925-1
SUSE-SU-2019:0831-1
USN-3859-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Libarchive