CVE-2019-19221
published 2019-11-21CVE-2019-19221: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.66%
47.9th percentile
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libarchive | < libarchive 3.4.2-1 (bookworm) | libarchive 3.4.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | — | — |
| libarchive | libarchive | >= 0 < 3.4.2-1 | 3.4.2-1 |
| libarchive | libarchive | >= 0 < 3.4.2-1 | 3.4.2-1 |
| libarchive | libarchive | >= 0 < 3.4.2-1 | 3.4.2-1 |
| libarchive | libarchive | >= 0 < 3.4.2-1 | 3.4.2-1 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8 | 3.1.2-11ubuntu0.16.04.8 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.6 | 3.2.2-3.1ubuntu0.6 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.6 | 3.6.0-1ubuntu1.6 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.6 | 3.7.2-2ubuntu0.6 |
| libarchive | libarchive | >= 0 < 3.7.7-0ubuntu3.1 | 3.7.7-0ubuntu3.1 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm4 | 3.1.2-7ubuntu2.8+esm4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm2 | 3.1.2-11ubuntu0.16.04.8+esm2 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm2 | 3.2.2-3.1ubuntu0.7+esm2 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.5+esm1 | 3.4.0-2ubuntu1.5+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2026-04-02·CVSS 5.5
CVE-2025-5916 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An at
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2020-03-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to cause a crash resulting in a denial
of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10.
(CVE-2020-9308)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
vendor_redhat·2019-11-21·CVSS 5.5
CVE-2019-19221 [MEDIUM] CWE-125 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Package: libarchive (Red Hat Enterprise Linux 6) - Out of support scope
Package: libarchive (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2019-19221: libarchive - In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an ...
vendor_debian·2019·CVSS 5.5
CVE-2019-19221 [MEDIUM] CVE-2019-19221: libarchive - In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an ...
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
bullseye: resolved (fixed in 3.4.2-1)
forky: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
OSV
libarchive vulnerabilities
osv·2026-04-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive
files. An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain RAR archive
files. If a user or automated system were tricked into processing a
specially crafted RAR archive, an attacker could possibly use this issue to
cause libarchive to crash, resulting in a denial of service, or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2024-20696)
It was discovered that libarchive incorrectly handled certain RAR archive
files. An attacker could possibly use this issue to execute arbitrary code
or c
GHSA
GHSA-m55v-6hqc-x3jh: In Libarchive 3
ghsa_unreviewed·2022-05-24
CVE-2019-19221 [LOW] CWE-125 GHSA-m55v-6hqc-x3jh: In Libarchive 3
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
OSV
libarchive vulnerabilities
osv·2020-03-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to cause a crash resulting in a denial
of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10.
(CVE-2020-9308)
OSV
CVE-2019-19221: In Libarchive 3
osv·2019-11-21·CVSS 5.5
CVE-2019-19221 [MEDIUM] CVE-2019-19221: In Libarchive 3
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c [fedora-all]
bugzilla·2020-02-11·CVSS 5.5
CVE-2019-19221 [MEDIUM] CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c [fedora-all]
CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
bugzilla·2020-02-11·CVSS 5.5
CVE-2019-19221 [MEDIUM] CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
CVE-2019-19221 libarchive: out-of-bounds read in archive_wstring_append_from_mbs in archive_string.c
A vulnerability was found in Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Reference:
https://github.com/libarchive/libarchive/commit/22b1db9d46654afc6f0c28f90af8cdc84a199f41
https://github.com/libarchive/libarchive/issues/1276
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1801636]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4443 https://access.redhat.com/errata/RHSA-2020:4443
---
This bug is now closed. Further updates for individual pr
Bugzilla
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
bugzilla·2019-11-07·CVSS 7.5
CVE-2019-18408 [HIGH] CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
CVE-2019-18408 libarchive: use-after-free in archive_read_format_rar_read_data when there is an error in the decompression of an archive entry [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
https://github.com/libarchive/libarchive/commit/22b1db9d46654afc6f0c28f90af8cdc84a199f41https://github.com/libarchive/libarchive/issues/1276https://lists.debian.org/debian-lts-announce/2022/04/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RHFV25AVTASTWZRF3KTSL357AQ6TYHM4/https://usn.ubuntu.com/4293-1/https://github.com/libarchive/libarchive/commit/22b1db9d46654afc6f0c28f90af8cdc84a199f41https://github.com/libarchive/libarchive/issues/1276https://lists.debian.org/debian-lts-announce/2022/04/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RHFV25AVTASTWZRF3KTSL357AQ6TYHM4/https://usn.ubuntu.com/4293-1/
2019-11-21
Published