Bug 48405 - libarchive: Multiple issues (4.2)
Summary: libarchive: Multiple issues (4.2)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 4.2
Hardware: All Linux
: P5 normal
Target Milestone: UCS 4.2-5-errata
Assignee: Quality Assurance
QA Contact: Philipp Hahn
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-03 08:21 CET by Quality Assurance
Modified: 2019-01-09 14:16 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 0.0 () Debian


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2019-01-03 08:21:12 CET
New Debian libarchive 3.1.2-11+deb8u6 fixes:
This update addresses the following issues:
* libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards  (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in  RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(),  realloc(rar->lzss.window, new_size) with new_size = 0 that can result in  Crash/DoS. This attack appear to be exploitable via the victim must open a  specially crafted RAR archive. (CVE-2018-1000877)
* libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards  (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability  in RAR decoder - libarchive/archive_read_support_format_rar.c that can  result in Crash/DoS - it is unknown if RCE is possible. This attack appear  to be exploitable via the victim must open a specially crafted RAR archive.  (CVE-2018-1000878)
Comment 1 Quality Assurance univentionstaff 2019-01-03 09:00:26 CET
--- mirror/ftp/4.2/unmaintained/component/4.2-5-errata/source/libarchive_3.1.2-11+deb8u5.dsc
+++ apt/ucs_4.2-0-errata4.2-5/source/libarchive_3.1.2-11+deb8u6.dsc
@@ -1,3 +1,12 @@
+3.1.2-11+deb8u6 [Fri, 21 Dec 2018 22:24:50 +0100] Markus Koschany <apo@debian.org>:
+
+  * Non-maintainer upload by the LTS team.
+  * Fix CVE-2018-1000877 and CVE-2018-1000878:
+    Daniel Axtens discovered a double-free and use-after-free vulnerability
+    in libarchive's RAR decoder that can result in a denial-of-service
+    (application crash) or may have other unspecified impact when a malformed
+    RAR archive is processed.
+
 3.1.2-11+deb8u5 [Thu, 29 Nov 2018 21:01:09 +0100] Markus Koschany <apo@debian.org>:
 
   * Non-maintainer upload by the LTS team.

<http://10.200.17.11/4.2-5/#2657342048020898213>
Comment 2 Philipp Hahn univentionstaff 2019-01-03 12:33:13 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.2-5] 4c1e1ee23e Bug #48405: libarchive 3.1.2-11+deb8u6
 doc/errata/staging/libarchive.yaml | 14 ++++++--------
 1 file changed, 6 insertions(+), 8 deletions(-)

[4.2-5] b46d21303a Bug #48405: libarchive 3.1.2-11+deb8u6
 doc/errata/staging/libarchive.yaml | 24 ++++++++++++++++++++++++
 1 file changed, 24 insertions(+)
Comment 3 Arvid Requate univentionstaff 2019-01-09 14:16:43 CET
<http://errata.software-univention.de/ucs/4.2/569.html>