Note:
This project will be discontinued after December 13, 2021. [more]
2017-09-17
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
Products | Libarchive |
Type | Out-of-bounds Read (CWE-125) |
First patch | - None (likely due to unavailable code) |
Links |
• https://www.debian.org/security/2018/dsa-4360
• https://github.com/libarchive/libarchive/issues/948 • https://usn.ubuntu.com/3736-1/ • https://bugs.debian.org/875960 • https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html |