CVE-2019-19221

Published

Severity

CVSS v3:
5.5 MEDIUM
CVSS v2:
2.1 LOW

Description

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:libarchive:libarchive:3.4.0:*:*:*:*:*:*:*n/an/a3.4.0
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*n/an/a32
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*n/an/a18.04
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*n/an/a19.10
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*n/an/a16.04
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0

External Links