CVE-2018-1000879

MEDIUM

libarchive <3.3.0 - NULL Pointer Dereference

Title source: llm
STIX 2.1

Description

libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.

References (8)

Core 8
Core References
Patch, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909
Third Party Advisory x_refsource_misc
https://github.com/libarchive/libarchive/pull/1105
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106324
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html

Scores

CVSS v3 6.5
EPSS 0.0069
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (5)
fedoraproject/fedora 28
fedoraproject/fedora 29
fedoraproject/fedora 30
libarchive/libarchive 3.3.0 - 3.4.0
opensuse/leap 15.0
Published Dec 20, 2018
Tracked Since Feb 18, 2026