Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-48958

Опубликовано: 10 окт. 2024
Источник: redhat
CVSS3: 7.8

Описание

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

A flaw was found in the libarchive library. An out-of-bounds access in the execute_filter_delta function in the libarchive/archive_read_support_format_rar.c file can be triggered due to a missing validation when a specially crafted RAR archive is processed. This issue may cause the application linked to the library to crash, resulting in denial of service.

Отчет

The libarchive library as shipped in Red Hat Enterprise Linux 6, 7, 8, 9 and Red Hat OpenShift Container Platform 4 is not affected by this vulnerability because the vulnerable code was introduced in a newer version of libarchive.

Меры по смягчению последствий

Do not process untrusted files with the libarchive library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveNot affected
Red Hat Enterprise Linux 7libarchiveNot affected
Red Hat Enterprise Linux 8libarchiveNot affected
Red Hat Enterprise Linux 9libarchiveNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2317728libarchive: Out-of-bounds access in libarchive's RAR file handling

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 месяцев назад

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

CVSS3: 7.8
nvd
8 месяцев назад

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

CVSS3: 7.8
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
8 месяцев назад

execute_filter_delta in archive_read_support_format_rar.c in libarchiv ...

CVSS3: 7.8
github
8 месяцев назад

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

7.8 High

CVSS3