cbcvebase.
CVE-2018-1000879
published 2018-12-20

CVE-2018-1000879: libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability…

PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.37%
87.4th percentile
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlibarchive< libarchive 3.3.3-2 (bookworm)libarchive 3.3.3-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libarchivelibarchive>= 0 < 3.3.3-23.3.3-2
libarchivelibarchive>= 0 < 3.3.3-23.3.3-2
libarchivelibarchive>= 0 < 3.3.3-23.3.3-2
libarchivelibarchive>= 0 < 3.3.3-23.3.3-2
libarchivelibarchive>= 3.3.0 < 3.4.03.4.0
opensuseleap

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.