system/libarchive: CVE-2018-1000879: NULL pointer dereference
Bugzilla ID | 220 |
Alias(es) | CVE-2018-1000879 |
Reporter | Max Rees (sroracle) |
Assignee | Max Rees (sroracle) |
Reported | 2019-10-24 16:31:17 -0500 |
Modified | 2019-10-24 16:32:27 -0500 |
Status | RESOLVED FIXED |
Version | 1.0-BETA3 |
Hardware | Adélie Linux / All |
Importance | --- / normal |
URL | https://nvd.nist.gov/vuln/detail/CVE-2018-1000879 |
Description
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205
onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer
Dereference vulnerability in ACL parser - libarchive/archive_acl.c,
archive_acl_from_text_l() that can result in Crash/DoS. This attack
appear to be exploitable via the victim must open a specially crafted
archive file.