CVE-2019-19221: Medium severity Libarchive libarchive vulnerability
Published Nov 21, 2019
·Updated
In Libarchive 3.4.0, archivewstringappendfrommbs in archivestring.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Affected Software
8 affected componentsFixes available
Libarchive libarchive=3.4.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
debian/libarchive
3.4.3-2+deb11u13.4.3-2+deb11u43.6.2-1+deb12u43.6.2-1+deb12u23.7.4-4+deb13u13.8.8-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libarchiveto a version that resolves this vulnerability.Fixed in 3.4.3-2+deb11u1Fixed in 3.4.3-2+deb11u4Fixed in 3.6.2-1+deb12u4Fixed in 3.6.2-1+deb12u2Fixed in 3.7.4-4+deb13u1Fixed in 3.8.8-2
Event History
Nov 21, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 3, 2026
Data Sourced
via Ubuntu·03:46 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:49 AM
Description
Jul 16, 2026
Data Sourced
via Debian·11:34 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-19221?
CVE-2019-19221 is a vulnerability in Libarchive 3.4.0 that allows for an out-of-bounds read.
2
What is the severity of CVE-2019-19221?
The severity of CVE-2019-19221 is medium.
3
How does CVE-2019-19221 affect Libarchive?
CVE-2019-19221 affects Libarchive 3.4.0.
4
How can I fix CVE-2019-19221?
To fix CVE-2019-19221, update to a version of Libarchive that is not affected by the vulnerability.
5
Where can I find more information about CVE-2019-19221?
You can find more information about CVE-2019-19221 on the official CVE website and the Libarchive GitHub page.