USN-7087-1: libarchive vulnerability
It was discovered that libarchive incorrectly handled certain RAR archive files. If a user or automated system were tricked into processing a specially crafted RAR archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7087-1?
USN-7087-1 is classified as a denial of service vulnerability due to improper handling of RAR archive files in libarchive.
How do I fix USN-7087-1?
To fix USN-7087-1, update your libarchive package to version 3.7.4-1ubuntu0.1 or newer for Ubuntu 24.10, 3.7.2-2ubuntu0.3 for Ubuntu 24.04, 3.6.0-1ubuntu1.3 for Ubuntu 22.04, or 3.4.0-2ubuntu1.4 for Ubuntu 20.04.
What is affected by USN-7087-1?
USN-7087-1 affects the libarchive package in Ubuntu, specifically versions below the patched releases mentioned.
Can USN-7087-1 be exploited remotely?
Yes, USN-7087-1 can potentially be exploited if a user or automated system is tricked into processing a specially crafted RAR archive.
Is USN-7087-1 a zero-day vulnerability?
USN-7087-1 is not categorized as a zero-day vulnerability, as it has been publicly disclosed and a patch has been made available.