Vulnerability Description
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libarchive | Libarchive | >= 3.3.0, < 3.4.0 |
| Fedoraproject | Fedora | 28 |
| Opensuse | Leap | 15.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106324Third Party AdvisoryVDB Entry
- https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909PatchThird Party Advisory
- https://github.com/libarchive/libarchive/pull/1105Third Party Advisory
- https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd870PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106324Third Party AdvisoryVDB Entry
- https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909PatchThird Party Advisory
- https://github.com/libarchive/libarchive/pull/1105Third Party Advisory
- https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd870PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2018-1000879?
CVE-2018-1000879 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c,...
How severe is CVE-2018-1000879?
CVE-2018-1000879 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000879?
Check the references section above for vendor advisories and patch information. Affected products include: Libarchive Libarchive, Fedoraproject Fedora, Opensuse Leap.