PT-2019-5148 · Libarchive+5 · Libarchive+5

Daxtens

·

Published

2019-01-20

·

Updated

2024-06-15

·

CVE-2019-1000020

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions v2.8.0 onwards
Description The issue is related to an infinite loop in the ISO9660 parser, specifically in the read CE() and parse rockridge() functions within the archive read support format iso9660.c file. This can result in a denial of service (DoS) when a victim opens a specially crafted ISO9660 file. The vulnerability is also described as a buffer memory read issue that can be exploited by a remote attacker using a specially crafted ISO9660 file to cause a denial of service.
Recommendations For libarchive versions v2.8.0 onwards, update to a version that includes a fix for the infinite loop issue in the ISO9660 parser. As a temporary workaround, consider restricting access to specially crafted ISO9660 files to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2522
ALT-PU-2019-3125
BDU:2020-01818
CESA-2019_2298
CESA-2019_3698
CVE-2019-1000020
DLA-1668-1
MGASA-2019-0074
OPENSUSE-SU-2019:1196-1
OPENSUSE-SU-2019:2615-1
OPENSUSE-SU-2019:2632-1
OPENSUSE-SU-2019_1196-1
OPENSUSE-SU-2019_2615-1
OPENSUSE-SU-2019_2632-1
OPENSUSE-SU-2024:10925-1
RHSA-2019:2298
RHSA-2019:3698
RHSA-2019_2298
RHSA-2019_3698
SUSE-SU-2019:0831-1
SUSE-SU-2019:3092-1
SUSE-SU-2019:3093-1
USN-3884-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive