Описание
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.8.7-1 |
| esm-infra-legacy/trusty | released | 3.1.2-7ubuntu2.8+esm5 |
| esm-infra-legacy/xenial | released | 3.1.2-11ubuntu0.16.04.8+esm3 |
| esm-infra/bionic | released | 3.2.2-3.1ubuntu0.7+esm3 |
| esm-infra/focal | released | 3.4.0-2ubuntu1.5+esm2 |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 3.6.0-1ubuntu1.7 |
| noble | released | 3.7.2-2ubuntu0.7 |
| questing | released | 3.7.7-0ubuntu3.2 |
| resolute | released | 3.8.5-1ubuntu2.1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
A flaw was found in libarchive. This heap out-of-bounds read vulnerabi ...
EPSS
7.5 High
CVSS3