First published: Thu Nov 21 2019(Updated: )
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libarchive Libarchive | =3.4.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
ubuntu/libarchive | <3.2.2-3.1ubuntu0.6 | 3.2.2-3.1ubuntu0.6 |
ubuntu/libarchive | <3.4.0-1ubuntu0.1 | 3.4.0-1ubuntu0.1 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.4.0-1ubuntu2 | 3.4.0-1ubuntu2 |
ubuntu/libarchive | <3.1.2-11ubuntu0.16.04.8 | 3.1.2-11ubuntu0.16.04.8 |
debian/libarchive | 3.4.3-2+deb11u1 3.6.2-1+deb12u1 3.7.2-2.1 3.7.4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19221 is a vulnerability in Libarchive 3.4.0 that allows for an out-of-bounds read.
The severity of CVE-2019-19221 is medium.
CVE-2019-19221 affects Libarchive 3.4.0.
To fix CVE-2019-19221, update to a version of Libarchive that is not affected by the vulnerability.
You can find more information about CVE-2019-19221 on the official CVE website and the Libarchive GitHub page.