漏洞信息详情
libarchive 数字错误漏洞
漏洞简介
libarchive是一款多格式存档和压缩库。
libarchive 3.3.2版本中的archive_read_support_format_rar.c文件的read_header存在数字错误漏洞。攻击者可利用该漏洞造成拒绝服务(‘archive_read_format_rar_read_header’函数越边界读取)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/libarchive/libarchive/commit/5562545b5562f6d12a4ef991fae158bf4ccf92b6
参考网址
来源:MISC
链接:https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=573
来源:DEBIAN
链接:https://www.debian.org/security/2018/dsa-4360
来源:UBUNTU
链接:https://usn.ubuntu.com/3859-1/
来源:MISC
链接:https://github.com/libarchive/libarchive/commit/5562545b5562f6d12a4ef991fae158bf4ccf92b6
来源:MISC
链接:https://bugs.debian.org/875974
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html
来源:GENTOO
链接:https://security.gentoo.org/glsa/201908-11
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20193093-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20193092-1.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/154089/Gentoo-Linux-Security-Advisory-201908-11.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164192/Red-Hat-Security-Advisory-2021-3556-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163789/Red-Hat-Security-Advisory-2021-3119-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163496/Red-Hat-Security-Advisory-2021-2705-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2228
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021062703
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2657
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092220
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4511/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163747/Red-Hat-Security-Advisory-2021-3016-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163267/Red-Hat-Security-Advisory-2021-2532-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021061015
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021071516
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021062315
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10878841
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2365
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78214
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2180
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3141
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163276/Red-Hat-Security-Advisory-2021-2543-01.html
受影响实体
- Libarchive Libarchive:3.3.2<!--2000-1-1-->
补丁
- libarchive 安全漏洞的修复措施<!--2017-9-18-->
还没有评论,来说两句吧...