PT-2017-3768 · Libarchive+4 · Libarchive+4

Carnilo

·

Published

2017-09-16

·

Updated

2021-08-17

·

CVE-2017-14503

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libarchive version 3.3.2
Description: The issue is related to an out-of-bounds read within the lha read data none() function in archive read support format lha.c when extracting a specially crafted lha archive. This is connected to lha crc16. Exploitation of the issue may allow a remote attacker to gain unauthorized access to information using a specially created lha archive.
Recommendations: For libarchive version 3.3.2, as a temporary workaround, consider disabling the lha read data none() function until a patch is available. Restrict access to the archive read support format lha.c module to minimize the risk of exploitation. Avoid using the lha crc16 variable in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00928
CESA-2019_2298
CESA-2019_3698
CVE-2017-14503
DLA-1600-1
DSA-4360-1
MGASA-2018-0361
OPENSUSE-SU-2018_3690-1
OPENSUSE-SU-2018_3717-1
RHSA-2019:2298
RHSA-2019:3698
RHSA-2019_2298
RHSA-2019_3698
SUSE-RU-2021:2757-1
SUSE-SU-2018:3571-1
SUSE-SU-2018:3640-1
SUSE-SU-2018:3640-2
USN-3736-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Libarchive