CVE-2021-31566
- EPSS 0.04%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:05:55
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger...
CVE-2021-23177
- EPSS 0.04%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:51:19
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extrac...
CVE-2022-26280
- EPSS 0.12%
- Veröffentlicht 28.03.2022 22:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:57
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
CVE-2021-36976
- EPSS 0.19%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 03.11.2025 22:15:49
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
CVE-2020-21674
- EPSS 1.66%
- Veröffentlicht 15.10.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:46
Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE...
CVE-2020-9308
- EPSS 0.7%
- Veröffentlicht 20.02.2020 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:23
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
CVE-2019-19221
- EPSS 0.08%
- Veröffentlicht 21.11.2019 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:21
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
CVE-2019-18408
- EPSS 4.59%
- Veröffentlicht 24.10.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:12
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
CVE-2019-11463
- EPSS 0.2%
- Veröffentlicht 23.04.2019 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:07
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who...
CVE-2019-1000020
- EPSS 1.42%
- Veröffentlicht 04.02.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:41
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, rea...