Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18408

Опубликовано: 10 мая 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

A use-after-free vulnerability was discovered in libarchive in the way it processes RAR archives when there is an error in one of the archive's entries. An application that accepts untrusted RAR archives may be vulnerable to this flaw, which could allow a remote attacker to cause a denial of service or to potentially execute code.

Отчет

This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6 as they did not include support for RAR archives.

Меры по смягчению последствий

No known mitigation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveNot affected
Red Hat Enterprise Linux 7libarchiveFixedRHSA-2020:020322.01.2020
Red Hat Enterprise Linux 8libarchiveFixedRHSA-2020:027129.01.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionslibarchiveFixedRHSA-2020:024627.01.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1769979libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry

EPSS

Процентиль: 89%
0.04588
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

CVSS3: 7.5
nvd
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

CVSS3: 7.5
debian
больше 6 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c ...

CVSS3: 7.5
github
больше 3 лет назад

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

oracle-oval
около 6 лет назад

ELSA-2020-0271: libarchive security update (IMPORTANT)

EPSS

Процентиль: 89%
0.04588
Низкий

8.1 High

CVSS3