First published: Thu Feb 07 2019(Updated: )
It was discovered that libarchive incorrectly handled certain 7zip files. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-1000019, CVE-2019-1000020)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libarchive13 | <3.2.2-5ubuntu0.2 | 3.2.2-5ubuntu0.2 |
Ubuntu Ubuntu | =18.10 | |
All of | ||
ubuntu/libarchive13 | <3.2.2-3.1ubuntu0.3 | 3.2.2-3.1ubuntu0.3 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libarchive13 | <3.1.2-11ubuntu0.16.04.6 | 3.1.2-11ubuntu0.16.04.6 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libarchive13 | <3.1.2-7ubuntu2.8 | 3.1.2-7ubuntu2.8 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability IDs for these libarchive vulnerabilities are CVE-2019-1000019 and CVE-2019-1000020.
The severity level of the libarchive vulnerabilities is not provided.
These libarchive vulnerabilities can be exploited by an attacker to cause a denial of service.
The affected software for these libarchive vulnerabilities is libarchive13 version 3.2.2-5ubuntu0.2 (Ubuntu 18.10), libarchive13 version 3.2.2-3.1ubuntu0.3 (Ubuntu 18.04), libarchive13 version 3.1.2-11ubuntu0.16.04.6 (Ubuntu 16.04), and libarchive13 version 3.1.2-7ubuntu2.8 (Ubuntu 14.04).
To fix the libarchive vulnerabilities, update libarchive13 to the recommended versions: 3.2.2-5ubuntu0.2 for Ubuntu 18.10, 3.2.2-3.1ubuntu0.3 for Ubuntu 18.04, 3.1.2-11ubuntu0.16.04.6 for Ubuntu 16.04, and 3.1.2-7ubuntu2.8 for Ubuntu 14.04.