CVE-2011-1779Libarchive vulnerability

CWE-3998 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.5%
top 35.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 17

Description

Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDfreebsd/libarchive2.8.4, 2.8.5+1
debiandebian/libarchive< libarchive 3.0.4-2 (bookworm)
Debianlibarchive/libarchive< 3.0.4-2+3

🔴Vulnerability Details

2
GHSA
GHSA-xm97-4p58-pfr9: Multiple use-after-free vulnerabilities in libarchive 22022-05-17
OSV
CVE-2011-1779: Multiple use-after-free vulnerabilities in libarchive 22012-04-13

📋Vendor Advisories

2
Debian
CVE-2011-1779: libarchive - Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remo...2011
Red Hat
Libarchive multiple security issues2010-12-30

💬Community

3
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [epel-5]2012-01-12
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [fedora-all]2011-05-18
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues2011-05-18