[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

libarchive: Multiple vulnerabilities (CVE-2019-19221, 2020-9308)

ID: oval:org.secpod.oval:def:1801698Date: (C)2020-12-22   (M)2023-11-10
Class: PATCHFamily: unix




A vulnerability was found in Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header , leading to a SIGSEGV or possibly unspecified other impact.

Platform:
Alpine Linux 3.12
Product:
libarchive
Reference:
11291
CVE-2019-19221
CVE-2020-9308
CVE    2
CVE-2020-9308
CVE-2019-19221

© SecPod Technologies