PT-2018-2542 · Libarchive+3 · Libarchive+3
Published
2018-09-28
·
Updated
2024-06-15
·
CVE-2018-1000880
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libarchive versions 3.2.0 and later
Description
The issue is related to improper input validation in the WARC parser, specifically in the
warc read() function within archive read support format warc.c. This can lead to a denial of service (DoS) due to quasi-infinite runtime and disk usage from a tiny, specially crafted WARC file. The attack is exploitable if the victim opens such a crafted file, potentially allowing a remote attacker to cause a service disruption.Recommendations
For libarchive versions 3.2.0 and later, consider disabling the WARC parsing functionality until a patch is available to prevent exploitation. Restrict access to the
warc read() function in archive read support format warc.c to minimize the risk of denial of service attacks. Avoid opening untrusted or specially crafted WARC files with the affected libarchive versions.Fix
DoS
Buffer Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Libarchive