CVE-2021-36976

MEDIUM

libarchive 3.4.1-3.5.1 - Use-After-Free in copy_string

Title source: llm
STIX 2.1

Description

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

References (11)

Core 11
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32375
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213183
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213182
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213193
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Mar/28
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Mar/29
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Mar/27
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-26

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-416
Status published
Products (8)
apple/ipados < 15.4
apple/iphone_os < 15.4
apple/macos < 12.3
apple/watchos < 8.5
fedoraproject/fedora 35
libarchive/libarchive 3.4.1 - 3.5.2
splunk/universal_forwarder 9.1.0
splunk/universal_forwarder 8.2.0 - 8.2.12
Published Jul 20, 2021
Tracked Since Feb 18, 2026