First published: Thu Dec 20 2018(Updated: )
A use-after-free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash. Upstream issue: <a href="https://github.com/libarchive/libarchive/pull/1105">https://github.com/libarchive/libarchive/pull/1105</a> Upstream patch: <a href="https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28">https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libarchive Libarchive | >=3.1.0<3.4.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
openSUSE Leap | =15.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
debian/libarchive | 3.4.3-2+deb11u1 3.6.2-1+deb12u1 3.7.4-1 | |
F5 BIG-IP | >=17.1.0<=17.1.1 | |
F5 BIG-IP | >=16.1.0<=16.1.5 | |
F5 BIG-IP | >=15.1.0<=15.1.10 | |
F5 BIG-IQ Centralized Management | >=8.2.0<=8.3.0 | |
F5 Traffix SDC | =5.2.0 |
https://github.com/libarchive/libarchive/pull/1105/commits/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000878 is a vulnerability in libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards that can result in Crash/DoS.
CVE-2018-1000878 has a severity rating of 8.8 (high).
CVE-2018-1000878 affects libarchive versions 3.1.0 to 3.4.0.
To fix CVE-2018-1000878, update libarchive to version 3.1.2-7ubuntu2.7 (for Ubuntu Trusty), 3.1.2-11ubuntu0.16.04.5 (for Ubuntu Xenial), 3.2.2-3.1ubuntu0.2 (for Ubuntu Bionic), or 3.2.2-5ubuntu0.1 (for Ubuntu Cosmic).
CWE-416 is a vulnerability that refers to Use After Free.