First published: Thu Oct 24 2019(Updated: )
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libarchive | <3.4.0 | 3.4.0 |
Libarchive Libarchive | <3.4.0 | |
Linux Linux kernel | ||
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
All of | ||
Libarchive Libarchive | <3.4.0 | |
Linux Linux kernel | ||
ubuntu/libarchive | <3.2.2-3.1ubuntu0.5 | 3.2.2-3.1ubuntu0.5 |
ubuntu/libarchive | <3.3.3-4ubuntu0.1 | 3.3.3-4ubuntu0.1 |
ubuntu/libarchive | <3.1.2-7ubuntu2.8+ | 3.1.2-7ubuntu2.8+ |
ubuntu/libarchive | <3.1.2-11ubuntu0.16.04.7 | 3.1.2-11ubuntu0.16.04.7 |
debian/libarchive | 3.4.3-2+deb11u1 3.6.2-1+deb12u1 3.7.4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18408 is a vulnerability in libarchive before version 3.4.0 that allows for a use-after-free in a certain ARCHIVE_FAILED situation.
CVE-2019-18408 has a severity rating of 7.5 (High).
The affected software for CVE-2019-18408 includes libarchive versions before 3.4.0 on Red Hat, Ubuntu, Debian, Canonical Ubuntu Linux, and Linux kernel.
To fix CVE-2019-18408, update to libarchive version 3.4.0 or later.
You can find more information about CVE-2019-18408 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.html, http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.html, https://access.redhat.com/errata/RHSA-2020:0203.