First published: Tue Apr 23 2019(Updated: )
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libarchive Libarchive | <3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11463 is a vulnerability in libarchive 3.3.4-dev that allows remote attackers to cause a denial of service via a crafted ZIP file due to a memory leak.
CVE-2019-11463 affects users who downloaded the development code of libarchive from GitHub.
The severity of CVE-2019-11463 is medium with a CVSSv3 score of 5.5.
To fix CVE-2019-11463, users should update to a version of libarchive that is higher than 3.4.0.
More information about CVE-2019-11463 can be found at the following references: [1] [2] [3].