Out-of-bounds read in libarchive - CVE-2019-19221
Published: November 22, 2019 / Updated: June 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in "archive_wstring_append_from_mbs" in "archive_string.c" because of an incorrect "mbrtowc" or "mbtowc" call. A remote attacker can create a specially crafted archive file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
VLC Media Player
libarchive (Alpine package)
libarchive (Ubuntu package)
libarchive (Red Hat package)
libarchive
bsdtar
libarchive13-debuginfo
libarchive13
libarchive-devel
libarchive-debugsource
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
Ubuntu
Fedora
How to mitigate CVE-2019-19221
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
VLC Media Player - update to 3.0.11
libarchive (Alpine package) - update to 3.3.3-r2
libarchive (Ubuntu package) - addressed in versions 3.1.2-7ubuntu2.8+esm4, 3.1.2-11ubuntu0.16.04.8, 3.1.2-11ubuntu0.16.04.8+esm2, 3.2.2-3.1ubuntu0.6, 3.2.2-3.1ubuntu0.7+esm2, 3.4.0-1ubuntu0.1, 3.4.0-2ubuntu1.5+esm1, 3.6.0-1ubuntu1.6, 3.7.2-2ubuntu0.6, 3.7.7-0ubuntu3.1
Quay - update to 3.3.3
libarchive (Red Hat package) - update to 3.3.2-9.el8
libarchive - update to 3.3.3-3.0.1
bsdtar - update to 3.3.3-3.0.1
libarchive - addressed in versions 3.3.3-7.fc29, 3.3.3-7.fc30, 3.4.2-1.fc32
libarchive13-debuginfo - update to 3.3.3-32.5.1
libarchive13 - update to 3.3.3-32.5.1
libarchive-devel - update to 3.3.3-32.5.1
libarchive-debugsource - update to 3.3.3-32.5.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Libarchive
- Ubuntu update for libarchive
- Multiple vulnerabilities in VLC Media Player
- Out-of-bounds read in libarchive (Alpine package)
- Red Hat Enterprise Linux 8 update for libarchive
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- SUSE update for libarchive
- Anolis OS update for libarchive
- Fedora 30 update for libarchive
- Fedora 29 update for libarchive
- Fedora 32 update for libarchive
- Ubuntu update for libarchive