K000140964: libarchive vulnerabilities CVE-2018-1000877 and CVE-2018-1000878
Discription

Security Advisory Description CVE-2018-1000877 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder – libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive. CVE-2018-1000878 ibarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder – libarchive/archive_read_support_format_rar.c that can result in Crash/DoS – it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive. Impact This vulnerability may result in a denial-of-service (DoS) of the feature using the affected…Read More

Back to Main

Subscribe for the latest news: