PT-2021-3660 · Unknown+7 · Libarchive+7
Florian Weimer
+1
·
Published
2021-03-22
·
Updated
2024-11-11
·
CVE-2021-36976
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libarchive versions 3.4.1 through 3.5.1
Description
The issue is related to a use-after-free in the
copy string function, which is called from do uncompress block and process block functions. This can allow a remote attacker to execute arbitrary code and affect the system, potentially leading to a denial of service. The vulnerability is associated with the use of memory after it has been freed.Recommendations
For libarchive versions 3.4.1 through 3.5.1, consider disabling the
copy string function as a temporary workaround until a patch is available. Restrict access to the do uncompress block and process block functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Apple Macos
Suse
Ubuntu
Windows
Libarchive