Описание
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 3.2.2-3.1ubuntu0.2 |
| cosmic | released | 3.2.2-5ubuntu0.1 |
| devel | released | 3.3.3-2 |
| esm-infra-legacy/trusty | released | 3.1.2-7ubuntu2.7 |
| esm-infra/bionic | released | 3.2.2-3.1ubuntu0.2 |
| esm-infra/xenial | released | 3.1.2-11ubuntu0.16.04.5 |
| precise/esm | DNE | |
| trusty | released | 3.1.2-7ubuntu2.7 |
| trusty/esm | released | 3.1.2-7ubuntu2.7 |
| upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onw ...
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
Уязвимость библиотеки для работы с архивами Libarchive, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3