First published: Thu Dec 20 2018(Updated: )
A double free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash. Upstream issue: <a href="https://github.com/libarchive/libarchive/pull/1105">https://github.com/libarchive/libarchive/pull/1105</a> Upstream patch: <a href="https://github.com/libarchive/libarchive/pull/1105/commits/021efa522ad729ff0f5806c4ce53e4a6cc1daa31">https://github.com/libarchive/libarchive/pull/1105/commits/021efa522ad729ff0f5806c4ce53e4a6cc1daa31</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libarchive Libarchive | >=3.1.0<3.4.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
debian/libarchive | 3.4.3-2+deb11u1 3.6.2-1+deb12u1 3.7.4-1 | |
F5 BIG-IP | >=17.1.0<=17.1.1 | |
F5 BIG-IP | >=16.1.0<=16.1.5 | |
F5 BIG-IP | >=15.1.0<=15.1.10 | |
F5 BIG-IQ Centralized Management | >=8.2.0<=8.3.0 | |
F5 Traffix SDC | =5.2.0 |
https://github.com/libarchive/libarchive/pull/1105/commits/021efa522ad729ff0f5806c4ce53e4a6cc1daa31
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000877 is a vulnerability in libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards).
libarchive versions between 3.1.0 and 3.4.0 are affected by CVE-2018-1000877.
CVE-2018-1000877 has a severity of 8.8 (high).
To fix CVE-2018-1000877, update libarchive to version 3.1.2-7ubuntu2.7 (for Ubuntu trusty), 3.1.2-11ubuntu0.16.04.5 (for Ubuntu xenial), 3.2.2-3.1ubuntu0.2 (for Ubuntu bionic), 3.2.2-5ubuntu0.1 (for Ubuntu cosmic), or any of the fixed versions provided by Debian.
You can find more information about CVE-2018-1000877 at these references: [Bug report in Launchpad](https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909) and [GitHub pull request](https://github.com/libarchive/libarchive/pull/1105).