First published: Mon Mar 02 2020(Updated: )
It was discovered that libarchive incorrectly handled certain archive files. An attacker could possibly use this issue to access sensitive information. (CVE-2019-19221) It was discovered that libarchive incorrectly handled certain archive files. An attacker could possibly use this issue to cause a crash resulting in a denial of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10. (CVE-2020-9308)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libarchive13 | <3.4.0-1ubuntu0.1 | 3.4.0-1ubuntu0.1 |
=19.10 | ||
All of | ||
ubuntu/libarchive13 | <3.2.2-3.1ubuntu0.6 | 3.2.2-3.1ubuntu0.6 |
=18.04 | ||
All of | ||
ubuntu/libarchive13 | <3.1.2-11ubuntu0.16.04.8 | 3.1.2-11ubuntu0.16.04.8 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is CVE-2019-19221.
The vulnerability in libarchive could allow an attacker to access sensitive information.
Versions 3.4.0-1ubuntu0.1, 3.2.2-3.1ubuntu0.6, and 3.1.2-11ubuntu0.16.04.8 of libarchive are affected by this vulnerability.
Yes, the remediation for this vulnerability is to update to version 3.4.0-1ubuntu0.1 of libarchive.
You can find more information about this vulnerability on the Ubuntu Security website and the CVE-2019-19221 reference.