CVE-2017-5601

An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:3.2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 03:27

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/95837 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/95837 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037974 - () http://www.securitytracker.com/id/1037974 -
References () https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9 - Issue Tracking, Patch, Third Party Advisory () https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9 - Issue Tracking, Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html - () https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html -
References () https://secunia.com/secunia_research/2017-3/ - () https://secunia.com/secunia_research/2017-3/ -

Information

Published : 2017-01-27 22:59

Updated : 2024-11-21 03:27


NVD link : CVE-2017-5601

Mitre link : CVE-2017-5601

CVE.ORG link : CVE-2017-5601


JSON object : View

Products Affected

libarchive

  • libarchive
CWE
CWE-125

Out-of-bounds Read