Описание
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-03-31 |
| esm-infra-legacy/trusty | deferred | 2026-03-31 |
| esm-infra/bionic | deferred | 2026-03-31 |
| esm-infra/focal | deferred | 2026-03-31 |
| esm-infra/xenial | deferred | 2026-03-31 |
| jammy | deferred | 2026-03-31 |
| noble | deferred | 2026-03-31 |
| questing | deferred | 2026-03-31 |
| upstream | needs-triage |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
A flaw was found in libarchive. This heap out-of-bounds read vulnerabi ...
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.
7.5 High
CVSS3