PT-2020-5166 · Libarchive+2 · Libarchive+2
Antekone
·
Published
2020-02-01
·
Updated
2022-01-01
·
CVE-2020-9308
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libarchive versions prior to 3.4.2
Description
The issue is related to errors in input data validation in the archive read support format rar5.c file of the libarchive library. This can lead to a denial of service when handling RAR5 files with invalid or corrupted headers. A remote attacker can exploit this issue by providing specially crafted RAR5 files.
Recommendations
For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the handling of RAR5 files until the update is applied.
Fix
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Libarchive