CVE-2020-9308: High severity Libarchive libarchive vulnerability
archivereadsupportformatrar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libarchiveto a version that resolves this vulnerability.Fixed in 3.4.3-2+deb11u1Fixed in 3.4.3-2+deb11u4Fixed in 3.6.2-1+deb12u4Fixed in 3.6.2-1+deb12u2Fixed in 3.7.4-4+deb13u1Fixed in 3.8.8-2 - Upgrade
Upgrade
libarchiveto a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is CVE-2020-9308?
CVE-2020-9308 is a vulnerability in libarchive that allows for a SIGSEGV or other unspecified impact when attempting to unpack a RAR5 file with an invalid or corrupted header.
What is the severity of CVE-2020-9308?
The severity of CVE-2020-9308 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2020-9308?
Versions 3.4.0-1ubuntu0.1 and below of libarchive in Ubuntu, versions 3.3.3-4+deb10u1, 3.3.3-4+deb10u3, 3.4.3-2+deb11u1, 3.6.2-1, and 3.7.2-1 of libarchive in Debian, and versions up to and including 3.4.2 of Libarchive are affected.
How can I fix CVE-2020-9308?
Upgrade to version 3.4.2 or later of libarchive to fix CVE-2020-9308.
Where can I find more information about CVE-2020-9308?
You can find more information about CVE-2020-9308 on the following links: [link1], [link2], [link3].