Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18408

Опубликовано: 24 окт. 2019
Источник: debian
EPSS Низкий

Описание

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libarchivefixed3.4.0-1package

Примечания

  • https://github.com/libarchive/libarchive/commit/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14689

EPSS

Процентиль: 89%
0.04588
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

CVSS3: 8.1
redhat
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

CVSS3: 7.5
nvd
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

CVSS3: 7.5
github
больше 3 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

oracle-oval
около 6 лет назад

ELSA-2020-0271: libarchive security update (IMPORTANT)

EPSS

Процентиль: 89%
0.04588
Низкий