Off-by-one in libarchive - CVE-2017-14502

 

Off-by-one in libarchive - CVE-2017-14502

Published: November 19, 2018


Vulnerability identifier: #VU15954
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14502
CWE-ID: CWE-193
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to off-by-one error for UTF-16 names in RAR archives. A remote attacker can trigger an out-of-bounds read in archive_read_format_rar_read_header and cause the service to crash.


Affected software

libarchive
Debian Linux
Gentoo Linux
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Opensuse
Fedora
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Service Telemetry Framework
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
libarchive (Alpine package)
libarchive (Red Hat package)
libarchive
Web Terminal

How to mitigate CVE-2017-14502

Install updates from vendor's website.

Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
libarchive (Alpine package) - update to 3.3.3-r0
libarchive (Red Hat package) - update to 3.3.3-1.el8
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
libarchive - addressed in versions 3.3.3-1.fc28, 3.3.3-1.fc29

External References

Related Security Bulletins