CVE-2021-36976Use After Free in Libarchive

CWE-416Use After Free12 documents9 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 58.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 24

Description

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

Debianlibarchive/libarchive< 3.4.3-2+deb11u2+3
NVDlibarchive/libarchive3.4.13.5.2
NVDapple/macos< 12.3
NVDapple/ipados< 15.4
NVDapple/watchos< 8.5

Also affects: Fedora 35

🔴Vulnerability Details

4
GHSA
GHSA-4fxq-mcvv-8fqm: libarchive 32022-05-24
OSV
libarchive vulnerabilities2022-02-17
OSV
CVE-2021-36976: libarchive 32021-07-20
CVEList
CVE-2021-36976: libarchive 32021-07-20

📋Vendor Advisories

7
Apple
CVE-2021-36976: macOS Monterey 12.32022-03-14
Apple
CVE-2021-36976: watchOS 8.52022-03-14
Apple
CVE-2021-36976: iOS 15.4 and iPadOS 15.42022-03-14
Ubuntu
libarchive vulnerabilities2022-02-17
Microsoft
Libarchive Remote Code Execution Vulnerability2022-01-11
CVE-2021-36976 — Use After Free in Libarchive | cvebase