First published: Tue Oct 29 2019(Updated: )
It was discovered that libarchive incorrectly handled certain archive files. An attacker could possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libarchive13 | <3.3.3-4ubuntu0.1 | 3.3.3-4ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/libarchive13 | <3.2.2-3.1ubuntu0.5 | 3.2.2-3.1ubuntu0.5 |
=18.04 | ||
All of | ||
ubuntu/libarchive13 | <3.1.2-11ubuntu0.16.04.7 | 3.1.2-11ubuntu0.16.04.7 |
=16.04 | ||
All of | ||
ubuntu/libarchive13 | <3.1.2-7ubuntu2.8+esm1 | 3.1.2-7ubuntu2.8+esm1 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this libarchive vulnerability is CVE-2019-18408.
The severity of USN-4169-1 is high.
The versions of libarchive affected by this vulnerability are 3.3.3-4ubuntu0.1, 3.2.2-3.1ubuntu0.5, 3.1.2-11ubuntu0.16.04.7, and 3.1.2-7ubuntu2.8+esm1.
An attacker can exploit this vulnerability to execute arbitrary code.
To fix USN-4169-1, update libarchive to version 3.3.3-4ubuntu0.1 or later.