#VU16726 Double-free error in libarchive - CVE-2018-1000877
Published: December 20, 2018 / Updated: December 27, 2018
libarchive
libarchive
Description
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to double-free error in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0. A remote attacker can trick the victim into opening a specially crafted RAR archive and cause the service to crash.