libarchive: Double free in RAR decoder resulting in a denial of service
Published Dec 20, 2018
8.8
HIGHCVSS 3.1
EPSS 4.58%
Description
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
Affected products
No data.
Configuration 1
- ≥ 3.1.0 · < 3.4.0
Configuration 2
- 8.0
- 9.0
Configuration 3
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 4
- 28
- 29
- 30
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 7
libarchive-0:3.1.2-12.el7
Fixed · RHSA-2019:2298
Red Hat Enterprise Linux 8
libarchive-0:3.3.2-7.el8
Fixed · RHSA-2019:3698
Red Hat Enterprise Linux 6
libarchive
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libarchive-0:3.1.2-12.el7 | Fixed | RHSA-2019:2298 |
| Red Hat Enterprise Linux 8 | libarchive-0:3.3.2-7.el8 | Fixed | RHSA-2019:3698 |
| Red Hat Enterprise Linux 6 | libarchive | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of libarchive as shipped with Red Hat Enterprise Linux 7. This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/106324 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2298 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3698 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-1000877 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1663887 Issue Tracking
- https://github.com/libarchive/libarchive/pull/1105 x_refsource_MISCThird Party Advisory
- https://github.com/libarchive/libarchive/pull/1105/commits/021efa522ad729ff0f5806c4ce53e4a6cc1daa31 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00011.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000877
- https://usn.ubuntu.com/3859-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1000877
- https://www.debian.org/security/2018/dsa-4360 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.