CVE-2018-1000879: Null Pointer Dereference
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archiveacl.c, archiveaclfromtextl() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1000879.
What is the severity of CVE-2018-1000879?
The severity of CVE-2018-1000879 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-1000879?
libarchive versions commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) are affected by CVE-2018-1000879.
How does CVE-2018-1000879 vulnerability manifest?
CVE-2018-1000879 manifests as a NULL Pointer Dereference vulnerability in ACL parser in libarchive.
What is the recommended action for CVE-2018-1000879?
To mitigate the CVE-2018-1000879 vulnerability, users should update libarchive to version 3.4.0 or newer.