Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 699222 (CVE-2019-18408) - <app-arch/libarchive-3.4.0: use-after-free in a certain ARCHIVE_FAILED situation (CVE-2019-18408)
Summary: <app-arch/libarchive-3.4.0: use-after-free in a certain ARCHIVE_FAILED situat...
Status: RESOLVED FIXED
Alias: CVE-2019-18408
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-11-03 12:55 UTC by GLSAMaker/CVETool Bot
Modified: 2020-03-15 16:28 UTC (History)
1 user (show)

See Also:
Package list:
app-arch/libarchive-3.4.0 app-crypt/libb2-0.98.1-r2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2019-11-03 12:55:46 UTC
CVE-2019-18408 (https://nvd.nist.gov/vuln/detail/CVE-2019-18408):
  archive_read_format_rar_read_data in archive_read_support_format_rar.c in
  libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED
  situation, related to Ppmd7_DecodeSymbol.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-11-03 13:27:33 UTC
Let's stabilize 3.4.0 then.
Comment 2 Stabilization helper bot gentoo-dev 2019-11-03 15:03:29 UTC
An automated check of this bug failed - repoman reported dependency errors (43 lines truncated): 

> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: RDEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0/desktop) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
Comment 3 Stabilization helper bot gentoo-dev 2019-11-03 16:02:05 UTC
An automated check of this bug succeeded - the previous repoman errors are now resolved.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2019-11-05 00:54:29 UTC
arm64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2019-11-05 08:25:03 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2019-11-05 09:27:51 UTC
x86 stable
Comment 7 Rolf Eike Beer archtester 2019-11-06 20:15:58 UTC
sparc stable
Comment 8 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-11-08 08:32:33 UTC
s390 stable
Comment 9 Agostino Sarubbo gentoo-dev 2019-11-12 15:09:44 UTC
ppc64 stable
Comment 10 Rolf Eike Beer archtester 2019-11-12 18:11:24 UTC
hppa stable
Comment 11 Agostino Sarubbo gentoo-dev 2019-11-13 07:40:04 UTC
ppc stable
Comment 12 Agostino Sarubbo gentoo-dev 2019-11-14 11:57:12 UTC
ia64 stable
Comment 13 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-11-22 09:34:54 UTC
arm stable
Comment 14 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-11-22 09:35:20 UTC
m68k stable
Comment 15 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-11-22 09:35:43 UTC
sh stable
Comment 16 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2020-02-21 10:28:27 UTC
Cleanup done.
Comment 17 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-15 16:20:07 UTC
New GLSA request filed.
Comment 18 GLSAMaker/CVETool Bot gentoo-dev 2020-03-15 16:28:09 UTC
This issue was resolved and addressed in
 GLSA 202003-28 at https://security.gentoo.org/glsa/202003-28
by GLSA coordinator Thomas Deutschmann (whissi).