High severity8.8NVD Advisory· Published Feb 20, 2020· Updated Jun 17, 2026
CVE-2020-9308
CVE-2020-9308
Description
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*range: >=3.4.0,<3.4.2
- (no CPE)range: <3.4.2
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- libarchive/libarchivedescription
Patches
Vulnerability mechanics
References
7- bugs.chromium.org/p/oss-fuzz/issues/detailnvdIssue TrackingPatchThird Party Advisory
- github.com/libarchive/libarchive/pull/1326nvdPatchThird Party Advisory
- github.com/libarchive/libarchive/pull/1326/commits/94821008d6eea81e315c5881cdf739202961040anvdPatchThird Party Advisory
- security.gentoo.org/glsa/202003-28nvdThird Party Advisory
- usn.ubuntu.com/4293-1/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6OTE7GWASH2ZOVG5H3HEN5PR6B3KF7JB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J76F7VU7HC3GBKG5SAKTRBOFOI3RGO6M/nvd
News mentions
0No linked articles in our index yet.