CVE-2019-1000019
Published: February 4, 2019Last modified: November 9, 2023
Description
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 6.5 | 
| Attack Vector | NETWORK | 
| Attack complexity | LOW | 
| Privileges required | NONE | 
| User interaction | REQUIRED | 
| Scope | UNCHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | libarchive | Not affected (3.6.1-r2) | 
| Stream | libarchive | Not affected (3.7.1-r0) | 
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html
 - http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00012.html
 - http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00015.html
 - https://access.redhat.com/errata/RHSA-2019:2298
 - https://access.redhat.com/errata/RHSA-2019:3698
 - https://github.com/libarchive/libarchive/pull/1120
 - https://github.com/libarchive/libarchive/pull/1120/commits/65a23f5dbee4497064e9bb467f81138a62b0dae1
 - https://lists.debian.org/debian-lts-announce/2019/02/msg00013.html
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/
 - https://usn.ubuntu.com/3884-1/