First published: Mon Jan 07 2019(Updated: )
A use-after-free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash. Upstream issue: <a href="https://github.com/libarchive/libarchive/pull/1105">https://github.com/libarchive/libarchive/pull/1105</a> Upstream patch: <a href="https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28">https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Libarchive |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1663889 is classified as a use-after-free vulnerability which can cause application crashes.
To fix REDHAT-BUG-1663889, apply the upstream patch from the libarchive repository.
REDHAT-BUG-1663889 affects systems using the libarchive RAR decoder.
Currently, no official workaround has been provided for REDHAT-BUG-1663889.
Exploits related to REDHAT-BUG-1663889 could potentially result in crashes and denial of service.