CVE-2020-9308
published 2020-02-20CVE-2020-9308: archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of…
PriorityP339high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.25%
80.8th percentile
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libarchive | < libarchive 3.4.0-2 (bookworm) | libarchive 3.4.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | >= 0 < 3.4.0-2 | 3.4.0-2 |
| libarchive | libarchive | >= 0 < 3.4.0-2 | 3.4.0-2 |
| libarchive | libarchive | >= 0 < 3.4.0-2 | 3.4.0-2 |
| libarchive | libarchive | >= 0 < 3.4.0-2 | 3.4.0-2 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8 | 3.1.2-11ubuntu0.16.04.8 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.6 | 3.2.2-3.1ubuntu0.6 |
| libarchive | libarchive | >= 3.4.0 < 3.4.2 | 3.4.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgg9-26cw-p92x: archive_read_support_format_rar5
ghsa_unreviewed·2022-05-24
CVE-2020-9308 [MEDIUM] CWE-20 GHSA-mgg9-26cw-p92x: archive_read_support_format_rar5
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
OSV
libarchive vulnerabilities
osv·2020-03-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to cause a crash resulting in a denial
of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10.
(CVE-2020-9308)
OSV
CVE-2020-9308: archive_read_support_format_rar5
osv·2020-02-20·CVSS 8.8
CVE-2020-9308 [HIGH] CVE-2020-9308: archive_read_support_format_rar5
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2020-03-02·CVSS 5.5
CVE-2019-19221 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to cause a crash resulting in a denial
of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10.
(CVE-2020-9308)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
vendor_redhat·2020-02-02·CVSS 8.8
CVE-2020-9308 [HIGH] CWE-20 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
Statement: This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include support for RAR 5 archives.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat Enterprise Linux 7) - Not affected
Package: libarchive (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-9308: libarchive - archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack...
vendor_debian·2020·CVSS 8.8
CVE-2020-9308 [HIGH] CVE-2020-9308: libarchive - archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack...
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixed in 3.4.0-2)
bullseye: resolved (fixed in 3.4.0-2)
forky: resolved (fixed in 3.4.0-2)
sid: resolved (fixed in 3.4.0-2)
trixie: resolved (fixed in 3.4.0-2)
No detection rules found.
Bugzilla
CVE-2020-9308 libarchive3: libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [epel-6]
bugzilla·2020-02-21·CVSS 8.8
CVE-2020-9308 [HIGH] CVE-2020-9308 libarchive3: libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [epel-6]
CVE-2020-9308 libarchive3: libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
bugzilla·2020-02-21·CVSS 8.8
CVE-2020-9308 [HIGH] CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
References:
https://github.com/libarchive/libarchive/pull/1326
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20459
Upstream commit:
https://github.com/libarchive/libarchive/pull/1326/commits/94821008d6eea81e315c5881cdf739202961040a
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1805967]
Created libarchive3 tracking bugs for this issue:
Affects: epel-6 [bug 1805968]
---
Support for RAR5 was introduced in li
Bugzilla
CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [fedora-all]
bugzilla·2020-02-21·CVSS 8.8
CVE-2020-9308 [HIGH] CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [fedora-all]
CVE-2020-9308 libarchive: attempts to unpack a RAR5 file with an invalid or corrupted header leads to a SIGSEGV [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20459https://github.com/libarchive/libarchive/pull/1326https://github.com/libarchive/libarchive/pull/1326/commits/94821008d6eea81e315c5881cdf739202961040ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6OTE7GWASH2ZOVG5H3HEN5PR6B3KF7JB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J76F7VU7HC3GBKG5SAKTRBOFOI3RGO6M/https://security.gentoo.org/glsa/202003-28https://usn.ubuntu.com/4293-1/https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20459https://github.com/libarchive/libarchive/pull/1326https://github.com/libarchive/libarchive/pull/1326/commits/94821008d6eea81e315c5881cdf739202961040ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6OTE7GWASH2ZOVG5H3HEN5PR6B3KF7JB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J76F7VU7HC3GBKG5SAKTRBOFOI3RGO6M/https://security.gentoo.org/glsa/202003-28https://usn.ubuntu.com/4293-1/
2020-02-20
Published