Out-of-bounds read in libarchive - CVE-2017-5601
Published: January 28, 2017 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Affected software
libarchive (Alpine package)
libarchive
bsdtar
bsdtar-debuginfo
libarchive-debugsource
libarchive-devel
libarchive13
libarchive13-debuginfo
libarchive13-32bit
libarchive13-32bit-debuginfo
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
Fedora
Dell EMC VxRail Appliance
How to mitigate CVE-2017-5601
libarchive (Alpine package) - addressed in versions 3.2.2-r0, 3.2.2-r1
libarchive - addressed in versions 3.2.2-2.fc25, 3.2.2-4.fc26
bsdtar - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
bsdtar-debuginfo - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
libarchive-debugsource - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
libarchive-devel - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
libarchive13 - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
libarchive13-debuginfo - addressed in versions 3.4.2-150200.4.3.1, 3.5.1-150400.3.3.1
libarchive13-32bit - update to 3.5.1-150400.3.3.1
libarchive13-32bit-debuginfo - update to 3.5.1-150400.3.3.1
Dell EMC VxRail Appliance - update to 7.0.411