Out-of-bounds read in libarchive - CVE-2017-14501

 

Out-of-bounds read in libarchive - CVE-2017-14501

Published: November 12, 2018 / Updated: November 13, 2018


Vulnerability identifier: #VU15818
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14501
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to out-of-bounds read condition in the parse_file_info function, as defined in the archive_read_support_format_iso9660.c source code file when extracting ISO 9660 files. A remote attacker can trick the victim into extracting an ISO 9660 file that submits malicious input and cause the service to crash.


Affected software

libarchive
Debian Linux
Gentoo Linux
Opensuse
Fedora
libarchive (Alpine package)
libarchive
Dell EMC Container Storage Modules
App Connect Enterprise Certified Container

How to mitigate CVE-2017-14501

Update to version 3.3.3.

libarchive - update to 3.3.3
libarchive (Alpine package) - update to 3.3.3-r0
Dell EMC Container Storage Modules - update to 1.7.0
libarchive - addressed in versions 3.3.3-1.fc28, 3.3.3-1.fc29
App Connect Enterprise Certified Container - update to 4.1.0

External References

Related Security Bulletins