Medium severity6.5NVD Advisory· Published Sep 17, 2017· Updated May 13, 2026
CVE-2017-14503
CVE-2017-14503
Description
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
Affected products
1- cpe:2.3:a:libarchive:libarchive:3.3.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- bugs.debian.org/875960nvdIssue TrackingMailing ListThird Party Advisory
- github.com/libarchive/libarchive/issues/948nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2298nvd
- access.redhat.com/errata/RHSA-2019:3698nvd
- lists.debian.org/debian-lts-announce/2018/11/msg00037.htmlnvd
- security.gentoo.org/glsa/201908-11nvd
- usn.ubuntu.com/3736-1/nvd
- www.debian.org/security/2018/dsa-4360nvd
News mentions
0No linked articles in our index yet.