CVE-2018-1000880

Published

Severity

CVSS v3:
6.5 MEDIUM
CVSS v2:
4.3 MEDIUM

Description

libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*3.2.0 (including)3.4.0*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*n/an/a16.04
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*n/an/a14.04
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*n/an/a18.04
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*n/an/a18.10
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*n/an/a15.0
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*n/an/a29
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*n/an/a30

External Links