CVE-2017-5601
published 2017-01-27CVE-2017-5601: An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.45%
90.4th percentile
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.1-6 (bookworm) | libarchive 3.2.1-6 (bookworm) |
| libarchive | libarchive | — | — |
| libarchive | libarchive | >= 0 < 3.2.1-6 | 3.2.1-6 |
| libarchive | libarchive | >= 0 < 3.2.1-6 | 3.2.1-6 |
| libarchive | libarchive | >= 0 < 3.2.1-6 | 3.2.1-6 |
| libarchive | libarchive | >= 0 < 3.2.1-6 | 3.2.1-6 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.4 | 3.1.2-7ubuntu2.4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.3 | 3.1.2-11ubuntu0.16.04.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7xm3-5xp5-q98v: An error in the lha_read_file_header_1() function (archive_read_support_format_lha
ghsa_unreviewed·2022-05-14
CVE-2017-5601 [HIGH] CWE-125 GHSA-7xm3-5xp5-q98v: An error in the lha_read_file_header_1() function (archive_read_support_format_lha
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
OSV
libarchive vulnerabilities
osv·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive incorrectly handled
recursive decompressions. A remote attacker could possibly use this issue
to cause libarchive to hang, resulting in a de
OSV
CVE-2017-5601: An error in the lha_read_file_header_1() function (archive_read_support_format_lha
osv·2017-01-27·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601: An error in the lha_read_file_header_1() function (archive_read_support_format_lha
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash, overwrite files, or run programs as your
login if it opened a specially crafted file.
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive in
Red Hat
libarchive: Out of bounds read in lha_read_file_header_1() function
vendor_redhat·2017-01-27·CVSS 7.5
CVE-2017-5601 [HIGH] CWE-20 libarchive: Out of bounds read in lha_read_file_header_1() function
libarchive: Out of bounds read in lha_read_file_header_1() function
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Statement: Red Hat Product Security has rated this issue as having Low security
impact. This issue is not currently planned to be addressed in future
updates. For additional information, refer to the Issue Severity
Classification: https://access.redhat.com/security/updates/classification.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-5601: libarchive - An error in the lha_read_file_header_1() function (archive_read_support_format_l...
vendor_debian·2017·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601: libarchive - An error in the lha_read_file_header_1() function (archive_read_support_format_l...
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Scope: local
bookworm: resolved (fixed in 3.2.1-6)
bullseye: resolved (fixed in 3.2.1-6)
forky: resolved (fixed in 3.2.1-6)
sid: resolved (fixed in 3.2.1-6)
trixie: resolved (fixed in 3.2.1-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-6]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-6]
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
There's no epel-6 libarchive p
Bugzilla
CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-5]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-5]
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-5.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fedora EPEL 5 changed to end-o
Bugzilla
CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [epel-7]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [epel-7]
CVE-2017-5601 python-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
python-liba
Bugzilla
CVE-2017-5601 mingw-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 mingw-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
CVE-2017-5601 mingw-libarchive: libarchive: Out of bounds read in lha_read_file_header_1() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function
bugzilla·2017-01-31·CVSS 7.5
CVE-2017-5601 [HIGH] CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function
CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function
A vulnerability was found in libarchive. There exists an out of bounds read in function lha_read_file_header_1(). A maliciously crafted file could cause the application to crash.
Upstream patch:
https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9
References:
https://secunia.com/secunia_research/2017-3/
Discussion:
Created libarchive tracking bugs for this issue:
Affects: epel-5 [bug 1417919]
Affects: epel-6 [bug 1417917]
Affects: fedora-all [bug 1417920]
Created mingw-libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1417918]
Created python-libarchive tracking bugs for this issue:
Affects: epel-7 [bug 1417922]
Affects: fedora-all [bug 1417921]
http://www.securityfocus.com/bid/95837http://www.securitytracker.com/id/1037974https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9https://lists.debian.org/debian-lts-announce/2018/11/msg00037.htmlhttps://secunia.com/secunia_research/2017-3/http://www.securityfocus.com/bid/95837http://www.securitytracker.com/id/1037974https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9https://lists.debian.org/debian-lts-announce/2018/11/msg00037.htmlhttps://secunia.com/secunia_research/2017-3/
2017-01-27
Published