PT-2020-5166 · Libarchive+2 · Libarchive+2

Antekone

·

Published

2020-02-01

·

Updated

2022-01-01

·

CVE-2020-9308

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions prior to 3.4.2
Description The issue is related to errors in input data validation in the archive read support format rar5.c file of the libarchive library. This can lead to a denial of service when handling RAR5 files with invalid or corrupted headers. A remote attacker can exploit this issue by providing specially crafted RAR5 files.
Recommendations For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the handling of RAR5 files until the update is applied.

Fix

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2870
ALT-PU-2020-2874
BDU:2020-05777
CVE-2020-9308
MGASA-2020-0127
USN-4293-1

Affected Products

Alt Linux
Ubuntu
Libarchive