REDHAT-BUG-1663889: Use After Free
Published Jan 7, 2019
·Updated
A use-after-free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash.
Upstream issue:
https://github.com/libarchive/libarchive/pull/1105
Upstream patch:
https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28
Affected Software
1 affected component
Libarchive libarchive
Event History
Jan 7, 2019
Data Sourced
via Red Hat·09:35 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1663889?
REDHAT-BUG-1663889 is classified as a use-after-free vulnerability which can cause application crashes.
2
How do I fix REDHAT-BUG-1663889?
To fix REDHAT-BUG-1663889, apply the upstream patch from the libarchive repository.
3
What systems are affected by REDHAT-BUG-1663889?
REDHAT-BUG-1663889 affects systems using the libarchive RAR decoder.
4
Is there a workaround for REDHAT-BUG-1663889?
Currently, no official workaround has been provided for REDHAT-BUG-1663889.
5
What exploits are associated with REDHAT-BUG-1663889?
Exploits related to REDHAT-BUG-1663889 could potentially result in crashes and denial of service.