PT-2021-3660 · Unknown+7 · Libarchive+7

Florian Weimer

+1

·

Published

2021-03-22

·

Updated

2024-11-11

·

CVE-2021-36976

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libarchive versions 3.4.1 through 3.5.1
Description The issue is related to a use-after-free in the copy string function, which is called from do uncompress block and process block functions. This can allow a remote attacker to execute arbitrary code and affect the system, potentially leading to a denial of service. The vulnerability is associated with the use of memory after it has been freed.
Recommendations For libarchive versions 3.4.1 through 3.5.1, consider disabling the copy string function as a temporary workaround until a patch is available. Restrict access to the do uncompress block and process block functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1454
ALT-PU-2022-1524
ALT-PU-2022-3332
AZL-6614
BDU:2021-03887
CVE-2021-36976
DLA-3950-1
MGASA-2022-0060
OESA-2021-1398
OPENSUSE-SU-2022:0944-1
OPENSUSE-SU-2022_0944-1
OPENSUSE-SU-2022_1930-1
OPENSUSE-SU-2024:11894-1
SUSE-SU-2022:0944-1
SUSE-SU-2022:0944-2
SUSE-SU-2022:1930-1
USN-5291-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Apple Macos
Suse
Ubuntu
Windows
Libarchive