PT-2019-5148 · Libarchive+5 · Libarchive+5
Daxtens
·
Published
2019-01-20
·
Updated
2024-06-15
·
CVE-2019-1000020
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libarchive versions v2.8.0 onwards
Description
The issue is related to an infinite loop in the ISO9660 parser, specifically in the
read CE() and parse rockridge() functions within the archive read support format iso9660.c file. This can result in a denial of service (DoS) when a victim opens a specially crafted ISO9660 file. The vulnerability is also described as a buffer memory read issue that can be exploited by a remote attacker using a specially crafted ISO9660 file to cause a denial of service.Recommendations
For libarchive versions v2.8.0 onwards, update to a version that includes a fix for the infinite loop issue in the ISO9660 parser.
As a temporary workaround, consider restricting access to specially crafted ISO9660 files to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive