CVE-2021-36976
published 2021-07-20CVE-2021-36976: libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.84%
85.1th percentile
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.4_and_ipados | — | — |
| apple | ipados | < 15.4 | 15.4 |
| apple | iphone_os | < 15.4 | 15.4 |
| apple | macos | < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| apple | watchos | < 8.5 | 8.5 |
| apple | watchos | — | — |
| debian | libarchive | < libarchive 3.6.0-1 (bookworm) | libarchive 3.6.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | >= 0 < 3.4.3-2+deb11u2 | 3.4.3-2+deb11u2 |
| libarchive | libarchive | >= 0 < 3.6.0-1 | 3.6.0-1 |
| libarchive | libarchive | >= 0 < 3.6.0-1 | 3.6.0-1 |
| libarchive | libarchive | >= 0 < 3.6.0-1 | 3.6.0-1 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.1 | 3.4.0-2ubuntu1.1 |
| libarchive | libarchive | 3.4.1 – 3.5.2 | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
| splunk | universal_forwarder | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fxq-mcvv-8fqm: libarchive 3
ghsa_unreviewed·2022-05-24
CVE-2021-36976 [MEDIUM] CWE-416 GHSA-4fxq-mcvv-8fqm: libarchive 3
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
OSV
libarchive vulnerabilities
osv·2022-02-17·CVSS 7.8
CVE-2021-23177 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled symlinks. If a
user or automated system were tricked into processing a specially crafted
archive, an attacker could possibly use this issue to change modes, times,
ACLs, and flags on arbitrary files. (CVE-2021-23177, CVE-2021-31566)
It was discovered that libarchive incorrectly handled certain RAR archives.
If a user or automated system were tricked into processing a specially
crafted RAR archive, an attacker could use this issue to cause libarchive
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-36976)
OSV
CVE-2021-36976: libarchive 3
osv·2021-07-20·CVSS 6.5
CVE-2021-36976 [MEDIUM] CVE-2021-36976: libarchive 3
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Apple
CVE-2021-36976: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 6.5
CVE-2021-36976 [MEDIUM] CVE-2021-36976: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2021-36976
Component: CVE-2021-36976
Apple
CVE-2021-36976: watchOS 8.5
vendor_apple·2022-03-14·CVSS 6.5
CVE-2021-36976 [MEDIUM] CVE-2021-36976: watchOS 8.5
Apple Security Update: About the security content of watchOS 8.5
Product: watchOS
Version: 8.5
CVE: CVE-2021-36976
Component: CVE-2021-36976
Apple
CVE-2021-36976: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 6.5
CVE-2021-36976 [MEDIUM] CVE-2021-36976: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2021-36976
Component: CVE-2021-36976
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2022-02-17·CVSS 7.8
CVE-2021-23177 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive incorrectly handled symlinks. If a
user or automated system were tricked into processing a specially crafted
archive, an attacker could possibly use this issue to change modes, times,
ACLs, and flags on arbitrary files. (CVE-2021-23177, CVE-2021-31566)
It was discovered that libarchive incorrectly handled certain RAR archives.
If a user or automated system were tricked into processing a specially
crafted RAR archive, an attacker could use this issue to cause libarchive
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-36976)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Libarchive Remote Code Execution Vulnerability
vendor_msrc·2022-01-11·CVSS 6.5
CVE-2021-36976 [MEDIUM] Libarchive Remote Code Execution Vulnerability
Libarchive Remote Code Execution Vulnerability
FAQ: Why is this a MITRE Corporation CVE?
CVE-2021-36976 is regarding a vulnerability in the libarchive open source library which is used by Windows. The January 2022 Windows Security Updates include the most recent version of this library which addresses the vulnerability and others. Please see libarchive CVEs for more information regarding all of the vulnerabilities that have been addressed.
Windows Libarchive: Windows Libarchive
MITRE Corporation: MITRE Corporation
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.a
Red Hat
libarchive: use-after-free in copy_string()
vendor_redhat·2021-06-22·CVSS 6.5
CVE-2021-36976 [MEDIUM] CWE-416 libarchive: use-after-free in copy_string()
libarchive: use-after-free in copy_string()
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
A use-after-free flaw was found in libarchive in the copy_string function.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat Enterprise Linux 7) - Not affected
Package: libarchive (Red Hat Enterprise Linux 8) - Not affected
Package: libarchive (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-36976: libarchive - libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from ...
vendor_debian·2021·CVSS 6.5
CVE-2021-36976 [MEDIUM] CVE-2021-36976: libarchive - libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from ...
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Scope: local
bookworm: resolved (fixed in 3.6.0-1)
bullseye: resolved (fixed in 3.4.3-2+deb11u2)
forky: resolved (fixed in 3.6.0-1)
sid: resolved (fixed in 3.6.0-1)
trixie: resolved (fixed in 3.6.0-1)
No detection rules found.
No public exploits indexed.
Krebs
‘Wormable’ Flaw Leads January 2022 Patch Tuesday
blogs_krebs·2022-01-11·CVSS 9.8
[CRITICAL] ‘Wormable’ Flaw Leads January 2022 Patch Tuesday
Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another.
Nine of the vulnerabilities fixed in this month’s Patch Tuesday received Microsoft’s “critical” rating, meaning malware or miscreants can exploit them to gain remote access to vulnerable Windows systems through no help from the user.
By all accounts, the most severe flaw addressed today is CVE-2022-21907, a critical, remote code exec
Krebs
‘Wormable’ Flaw Leads January 2022 Patch Tuesday
blogs_krebs·2022-01-11·CVSS 9.8
[CRITICAL] ‘Wormable’ Flaw Leads January 2022 Patch Tuesday
Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another.
Nine of the vulnerabilities fixed in this month’s Patch Tuesday received Microsoft’s “critical” rating, meaning malware or miscreants can exploit them to gain remote access to vulnerable Windows systems through no help from the user.
By all accounts, the most severe flaw addressed today is CVE-2022-21907, a critical, remote code exec
http://seclists.org/fulldisclosure/2022/Mar/27http://seclists.org/fulldisclosure/2022/Mar/28http://seclists.org/fulldisclosure/2022/Mar/29https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32375https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libarchive/OSV-2021-557.yamlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SE5NJQNM22ZE5Z55LPAGCUHSBQZBKMKC/https://security.gentoo.org/glsa/202208-26https://support.apple.com/kb/HT213182https://support.apple.com/kb/HT213183https://support.apple.com/kb/HT213193http://seclists.org/fulldisclosure/2022/Mar/27http://seclists.org/fulldisclosure/2022/Mar/28http://seclists.org/fulldisclosure/2022/Mar/29https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32375https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libarchive/OSV-2021-557.yamlhttps://lists.debian.org/debian-lts-announce/2024/11/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SE5NJQNM22ZE5Z55LPAGCUHSBQZBKMKC/https://security.gentoo.org/glsa/202208-26https://support.apple.com/kb/HT213182https://support.apple.com/kb/HT213183https://support.apple.com/kb/HT213193
2021-07-20
Published