CVE-2019-1000019
published 2019-02-04CVE-2019-1000019: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.41%
87.5th percentile
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libarchive | < libarchive 3.3.3-4 (bookworm) | libarchive 3.3.3-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | >= 0 < 3.3.3-4 | 3.3.3-4 |
| libarchive | libarchive | >= 0 < 3.3.3-4 | 3.3.3-4 |
| libarchive | libarchive | >= 0 < 3.3.3-4 | 3.3.3-4 |
| libarchive | libarchive | >= 0 < 3.3.3-4 | 3.3.3-4 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8 | 3.1.2-7ubuntu2.8 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.6 | 3.1.2-11ubuntu0.16.04.6 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.3 | 3.2.2-3.1ubuntu0.3 |
| libarchive | libarchive | >= 3.0.2 < 3.4.0 | 3.4.0 |
| opensuse | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2019-02-07·CVSS 6.5
CVE-2019-1000019 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain 7zip files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-1000019, CVE-2019-1000020)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
vendor_redhat·2019-01-20·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CWE-125 libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
Statement: This vulnerability is present in the libarchive package included in Red Hat Virtualization Hypervisor, however it is never exposed to archives created by attackers or users, so the vulnerability can not be exploited.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: redhat-virtualization-host
Debian
CVE-2019-1000019: libarchive - libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (rele...
vendor_debian·2019·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019: libarchive - libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (rele...
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
Scope: local
bookworm: resolved (fixed in 3.3.3-4)
bullseye: resolved (fixed in 3.3.3-4)
forky: resolved (fixed in 3.3.3-4)
sid: resolved (fixed in 3.3.3-4)
trixie: resolved (fixed in 3.3.3-4)
GHSA
GHSA-636v-c8v5-whhf: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3
ghsa_unreviewed·2022-05-13
CVE-2019-1000019 [MEDIUM] CWE-125 GHSA-636v-c8v5-whhf: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
OSV
libarchive vulnerabilities
osv·2019-02-07·CVSS 6.5
CVE-2019-1000019 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain 7zip files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-1000019, CVE-2019-1000020)
OSV
CVE-2019-1000019: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3
osv·2019-02-04·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1000019 CVE-2019-1000020 mingw-libarchive: various flaws [fedora-all]
bugzilla·2019-02-08·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019 CVE-2019-1000020 mingw-libarchive: various flaws [fedora-all]
CVE-2019-1000019 CVE-2019-1000020 mingw-libarchive: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2019-1000019 CVE-2019-1000020 libarchive3: various flaws [epel-6]
bugzilla·2019-02-06·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019 CVE-2019-1000020 libarchive3: various flaws [epel-6]
CVE-2019-1000019 CVE-2019-1000020 libarchive3: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg updat
Bugzilla
CVE-2019-1000019 CVE-2019-1000020 libarchive: various flaws [fedora-all]
bugzilla·2019-02-06·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019 CVE-2019-1000020 libarchive: various flaws [fedora-all]
CVE-2019-1000019 CVE-2019-1000020 libarchive: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2019-1000019 libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
bugzilla·2019-02-06·CVSS 6.5
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019 libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
CVE-2019-1000019 libarchive: Out of bounds read in archive_read_support_format_7zip.c resulting in a denial of service
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards
(release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in
7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can
result in a crash (denial of service). This attack appears to be exploitable via
the victim opening a specially crafted 7zip file.
References:
https://github.com/libarchive/libarchive/pull/1120/commits/65a23f5dbee4497064e9bb467f81138a62b0dae1
https://github.com/libarchive/libarchive/pull/1120
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1672900]
---
Created libarchive tracking bugs for this iss
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2019:2298https://access.redhat.com/errata/RHSA-2019:3698https://github.com/libarchive/libarchive/pull/1120https://github.com/libarchive/libarchive/pull/1120/commits/65a23f5dbee4497064e9bb467f81138a62b0dae1https://lists.debian.org/debian-lts-announce/2019/02/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/https://usn.ubuntu.com/3884-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2019:2298https://access.redhat.com/errata/RHSA-2019:3698https://github.com/libarchive/libarchive/pull/1120https://github.com/libarchive/libarchive/pull/1120/commits/65a23f5dbee4497064e9bb467f81138a62b0dae1https://lists.debian.org/debian-lts-announce/2019/02/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/https://usn.ubuntu.com/3884-1/
2019-02-04
Published