F5-K000140964: Use After Free
CVE-2018-1000877 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archivereadsupportformatrar.c, parsecodes(), realloc(rar->lzss.window, newsize) with newsize = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive. CVE-2018-1000878 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archivereadsupportformatrar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000140964?
The severity of F5-K000140964 is considered high due to the potential for a double free vulnerability in affected software.
How do I fix F5-K000140964?
To fix F5-K000140964, update your F5 BIG-IP, BIG-IQ, or Traffix systems to the recommended versions that mitigate this vulnerability.
Which versions of F5 products are affected by F5-K000140964?
F5-K000140964 affects multiple versions of F5 BIG-IP, BIG-IQ Centralized Management, and Traffix SDC within specific version ranges.
What kind of vulnerability is F5-K000140964?
F5-K000140964 is a CWE-415: Double Free vulnerability that occurs in the RAR decoder component of libarchive.
Is a patch available for F5-K000140964?
Yes, a patch is available that addresses the vulnerability in the affected versions of F5 software.