CVE-2019-11463: Medium severity oracle libarchive vulnerability
A memory leak in archivereadformatzipcleanup in archivereadsupportformatzip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVELZMAH typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11463?
CVE-2019-11463 is a vulnerability in libarchive 3.3.4-dev that allows remote attackers to cause a denial of service via a crafted ZIP file due to a memory leak.
How does CVE-2019-11463 affect users?
CVE-2019-11463 affects users who downloaded the development code of libarchive from GitHub.
What is the severity of CVE-2019-11463?
The severity of CVE-2019-11463 is medium with a CVSSv3 score of 5.5.
How can I fix CVE-2019-11463?
To fix CVE-2019-11463, users should update to a version of libarchive that is higher than 3.4.0.
Where can I find more information about CVE-2019-11463?
More information about CVE-2019-11463 can be found at the following references: [1] [2] [3].