Уязвимость использования после освобождения (use-after-free) в функции "copy_string" в libarchive
Описание
В libarchive существует уязвимость типа "использование после освобождения" (use-after-free) в функции copy_string
, которая вызывается из функций do_uncompress_block
и process_block
.
Затронутые версии ПО
- от версии 3.4.1 до версии 3.5.1 включительно
Тип уязвимости
Уязвимость типа "использование после освобождения" (use-after-free)
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (ca ...
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2