PT-2019-5147 · Libarchive+5 · Libarchive+5

Daxtens

·

Published

2019-01-20

·

Updated

2024-06-15

·

CVE-2019-1000019

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions 3.0.2 and later
Description The issue is related to an out-of-bounds read in the libarchive library, specifically in the 7zip decompression functionality. This can be exploited by a remote attacker using a specially crafted 7zip file, potentially leading to a denial of service. The vulnerable function is located in archive read support format 7zip.c, specifically in the header bytes() function.
Recommendations For libarchive versions 3.0.2 and later, consider avoiding the use of the 7zip decompression feature until a patch is available. As a temporary workaround, restrict access to specially crafted 7zip files to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2522
ALT-PU-2019-3125
BDU:2020-01817
CESA-2019_2298
CESA-2019_3698
CVE-2019-1000019
DLA-1668-1
MGASA-2019-0074
OPENSUSE-SU-2019:1196-1
OPENSUSE-SU-2019:2615-1
OPENSUSE-SU-2019:2632-1
OPENSUSE-SU-2019_1196-1
OPENSUSE-SU-2019_2615-1
OPENSUSE-SU-2019_2632-1
OPENSUSE-SU-2024:10925-1
RHSA-2019:2298
RHSA-2019:3698
RHSA-2019_2298
RHSA-2019_3698
SUSE-SU-2019:0831-1
SUSE-SU-2019:3092-1
SUSE-SU-2019:3093-1
USN-3884-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive