PT-2019-5148 · Libarchive+5 · Libarchive+5
Daxtens
·
Publicado
2019-01-20
·
Atualizado
2024-06-15
·
CVE-2019-1000020
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libarchive versions v2.8.0 onwards
Description
The issue is related to an infinite loop in the ISO9660 parser, specifically in the
read CE() and parse rockridge() functions within the archive read support format iso9660.c file. This can result in a denial of service (DoS) when a victim opens a specially crafted ISO9660 file. The vulnerability is also described as a buffer memory read issue that can be exploited by a remote attacker using a specially crafted ISO9660 file to cause a denial of service.Recommendations
For libarchive versions v2.8.0 onwards, update to a version that includes a fix for the infinite loop issue in the ISO9660 parser.
As a temporary workaround, consider restricting access to specially crafted ISO9660 files to minimize the risk of exploitation.
Correção
DoS
Resource Exhaustion
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive