PT-2018-2542 · Libarchive+3 · Libarchive+3

Published

2018-09-28

·

Updated

2024-06-15

·

CVE-2018-1000880

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions 3.2.0 and later
Description The issue is related to improper input validation in the WARC parser, specifically in the warc read() function within archive read support format warc.c. This can lead to a denial of service (DoS) due to quasi-infinite runtime and disk usage from a tiny, specially crafted WARC file. The attack is exploitable if the victim opens such a crafted file, potentially allowing a remote attacker to cause a service disruption.
Recommendations For libarchive versions 3.2.0 and later, consider disabling the WARC parsing functionality until a patch is available to prevent exploitation. Restrict access to the warc read() function in archive read support format warc.c to minimize the risk of denial of service attacks. Avoid opening untrusted or specially crafted WARC files with the affected libarchive versions.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2522
ALT-PU-2019-3125
BDU:2019-00927
CVE-2018-1000880
DSA-4360-1
MGASA-2019-0030
OPENSUSE-SU-2019:1196-1
OPENSUSE-SU-2019_1196-1
OPENSUSE-SU-2024:10925-1
SUSE-SU-2019:0831-1
USN-3859-1

Affected Products

Alt Linux
Suse
Ubuntu
Libarchive