rpm package
suse/libarchive&distro=SUSE Linux Enterprise Module for Development Tools 15 SP3
pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-36227 | — | < 3.4.2-150200.4.15.1 | 3.4.2-150200.4.15.1 | Nov 22, 2022 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties disp | ||
| CVE-2021-31566 | — | < 3.4.2-150200.4.12.1 | 3.4.2-150200.4.12.1 | Aug 23, 2022 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extr | ||
| CVE-2021-23177 | — | < 3.4.2-150200.4.9.1 | 3.4.2-150200.4.9.1 | Aug 23, 2022 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacke | ||
| CVE-2022-26280 | — | < 3.4.2-150200.4.6.1 | 3.4.2-150200.4.6.1 | Mar 28, 2022 | Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init. | ||
| CVE-2021-36976 | — | < 3.4.2-150200.4.3.1 | 3.4.2-150200.4.3.1 | Jul 20, 2021 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). | ||
| CVE-2017-5601 | Hig | 7.5 | < 3.4.2-150200.4.3.1 | 3.4.2-150200.4.3.1 | Jan 27, 2017 | An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive. |
- CVE-2022-36227Nov 22, 2022affected < 3.4.2-150200.4.15.1fixed 3.4.2-150200.4.15.1
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties disp
- CVE-2021-31566Aug 23, 2022affected < 3.4.2-150200.4.12.1fixed 3.4.2-150200.4.12.1
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extr
- CVE-2021-23177Aug 23, 2022affected < 3.4.2-150200.4.9.1fixed 3.4.2-150200.4.9.1
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacke
- CVE-2022-26280Mar 28, 2022affected < 3.4.2-150200.4.6.1fixed 3.4.2-150200.4.6.1
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
- CVE-2021-36976Jul 20, 2021affected < 3.4.2-150200.4.3.1fixed 3.4.2-150200.4.3.1
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
- affected < 3.4.2-150200.4.3.1fixed 3.4.2-150200.4.3.1
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.