PT-2019-3960 · Libarchive+4 · Libarchive+4

Published

2019-05-10

·

Updated

2024-06-15

·

CVE-2019-18408

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions prior to 3.4.0
Description The issue is related to a use-after-free bug in the archive read format rar read data function of the archive read support format rar.c module in the libarchive library. This bug can be exploited by a remote attacker to cause a denial of service, particularly in situations involving a failed archive and the Ppmd7 DecodeSymbol function.
Recommendations For versions prior to 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the archive read format rar read data function until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04476
CESA-2020_0203
CESA-2020_0271
CVE-2019-18408
DLA-1971-1
DSA-4557-1
OPENSUSE-SU-2019:2615-1
OPENSUSE-SU-2019:2632-1
OPENSUSE-SU-2019_2615-1
OPENSUSE-SU-2019_2632-1
OPENSUSE-SU-2024:10925-1
RHSA-2020:0203
RHSA-2020:0246
RHSA-2020:0271
RHSA-2020_0203
RHSA-2020_0271
SUSE-RU-2021:2757-1
SUSE-SU-2019:3092-1
SUSE-SU-2019:3093-1
USN-4169-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Libarchive