Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000878

Опубликовано: 20 дек. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

РелизСтатусПримечание
bionic

released

3.2.2-3.1ubuntu0.2
cosmic

released

3.2.2-5ubuntu0.1
devel

released

3.3.3-2
esm-infra-legacy/trusty

released

3.1.2-7ubuntu2.7
esm-infra/bionic

released

3.2.2-3.1ubuntu0.2
esm-infra/xenial

released

3.1.2-11ubuntu0.16.04.5
precise/esm

DNE

trusty

released

3.1.2-7ubuntu2.7
trusty/esm

released

3.1.2-7ubuntu2.7
upstream

needs-triage

Показывать по

EPSS

Процентиль: 82%
0.0171
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
около 7 лет назад

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

CVSS3: 8.8
nvd
около 7 лет назад

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

CVSS3: 8.8
debian
около 7 лет назад

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onw ...

CVSS3: 8.8
github
больше 3 лет назад

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

CVSS3: 8.8
fstec
около 7 лет назад

Уязвимость библиотеки для работы с архивами Libarchive, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 82%
0.0171
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3