CVE-2019-18408: Use After Free
archivereadformatrarreaddata in archivereadsupportformatrar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVEFAILED situation, related to Ppmd7DecodeSymbol.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-18408?
CVE-2019-18408 is a vulnerability in libarchive before version 3.4.0 that allows for a use-after-free in a certain ARCHIVE_FAILED situation.
How severe is CVE-2019-18408?
CVE-2019-18408 has a severity rating of 7.5 (High).
What is the affected software for CVE-2019-18408?
The affected software for CVE-2019-18408 includes libarchive versions before 3.4.0 on Red Hat, Ubuntu, Debian, Canonical Ubuntu Linux, and Linux kernel.
How can I fix CVE-2019-18408?
To fix CVE-2019-18408, update to libarchive version 3.4.0 or later.
Where can I find more information about CVE-2019-18408?
You can find more information about CVE-2019-18408 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.html, http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.html, https://access.redhat.com/errata/RHSA-2020:0203.