CVE-2019-18408
published 2019-10-24CVE-2019-18408: archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.04%
89.5th percentile
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libarchive | < libarchive 3.4.0-1 (bookworm) | libarchive 3.4.0-1 (bookworm) |
| libarchive | libarchive | < 3.4.0 | 3.4.0 |
| libarchive | libarchive | >= 0 < 3.4.0-1 | 3.4.0-1 |
| libarchive | libarchive | >= 0 < 3.4.0-1 | 3.4.0-1 |
| libarchive | libarchive | >= 0 < 3.4.0-1 | 3.4.0-1 |
| libarchive | libarchive | >= 0 < 3.4.0-1 | 3.4.0-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerability
vendor_ubuntu·2019-10-29
CVE-2019-18408 libarchive vulnerability
Title: libarchive vulnerability
Summary: libarchive could be made to execute arbitrary code if it received
specially crafted archive file.
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
vendor_redhat·2019-05-10·CVSS 7.5
CVE-2019-18408 [HIGH] CWE-416 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
A use-after-free vulnerability was discovered in libarchive in the way it processes RAR archives when there is an error in one of the archive's entries. An application that accepts untrusted RAR archives may be vulnerable to this flaw, which could allow a remote attacker to cause a denial of service or to potentially execute code.
Statement: This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6 as they did not include support for RAR
Debian
CVE-2019-18408: libarchive - archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarc...
vendor_debian·2019·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408: libarchive - archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarc...
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
Scope: local
bookworm: resolved (fixed in 3.4.0-1)
bullseye: resolved (fixed in 3.4.0-1)
forky: resolved (fixed in 3.4.0-1)
sid: resolved (fixed in 3.4.0-1)
trixie: resolved (fixed in 3.4.0-1)
GHSA
GHSA-4hj2-55w3-4qwh: archive_read_format_rar_read_data in archive_read_support_format_rar
ghsa_unreviewed·2022-05-24
CVE-2019-18408 [HIGH] CWE-416 GHSA-4hj2-55w3-4qwh: archive_read_format_rar_read_data in archive_read_support_format_rar
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
OSV
CVE-2019-18408: archive_read_format_rar_read_data in archive_read_support_format_rar
osv·2019-10-24·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408: archive_read_format_rar_read_data in archive_read_support_format_rar
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18408 libarchive3: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [epel-6]
bugzilla·2019-11-07·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408 libarchive3: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [epel-6]
CVE-2019-18408 libarchive3: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
bugzilla·2019-11-07·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2019-18408 mingw-libarchive: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
bugzilla·2019-11-07·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408 mingw-libarchive: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
CVE-2019-18408 mingw-libarchive: libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RP
Bugzilla
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
bugzilla·2019-11-07·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
Reference:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14689
Upstream commit:
https://github.com/libarchive/libarchive/commit/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1769980]
Created libarchive3 tracking bugs for this issue:
Affects: epel-6 [bug 1769982]
Created mingw-libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1769981]
---
While rea
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2020:0203https://access.redhat.com/errata/RHSA-2020:0246https://access.redhat.com/errata/RHSA-2020:0271https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14689https://github.com/libarchive/libarchive/commit/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60https://github.com/libarchive/libarchive/compare/v3.3.3...v3.4.0https://lists.debian.org/debian-lts-announce/2019/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LZ4VJGTCYEJSDLOEWUUFG6TM4SUPFSY/https://seclists.org/bugtraq/2019/Nov/2https://security.gentoo.org/glsa/202003-28https://support.f5.com/csp/article/K52144175?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4169-1/https://www.debian.org/security/2019/dsa-4557http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2020:0203https://access.redhat.com/errata/RHSA-2020:0246https://access.redhat.com/errata/RHSA-2020:0271https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14689https://github.com/libarchive/libarchive/commit/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60https://github.com/libarchive/libarchive/compare/v3.3.3...v3.4.0https://lists.debian.org/debian-lts-announce/2019/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LZ4VJGTCYEJSDLOEWUUFG6TM4SUPFSY/https://seclists.org/bugtraq/2019/Nov/2https://security.gentoo.org/glsa/202003-28https://support.f5.com/csp/article/K52144175?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4169-1/https://www.debian.org/security/2019/dsa-4557
2019-10-24
Published