Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 699222 (CVE-2019-18408) - <app-arch/libarchive-3.4.0: use-after-free in a certain ARCHIVE_FAILED situation (CVE-2019-18408)
Summary: <app-arch/libarchive-3.4.0: use-after-free in a certain ARCHIVE_FAILED situat...
Status: IN_PROGRESS
Alias: CVE-2019-18408
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa? stable]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-11-03 12:55 UTC by GLSAMaker/CVETool Bot
Modified: 2019-11-12 18:11 UTC (History)
7 users (show)

See Also:
Package list:
app-arch/libarchive-3.4.0 app-crypt/libb2-0.98.1-r2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2019-11-03 12:55:46 UTC
CVE-2019-18408 (https://nvd.nist.gov/vuln/detail/CVE-2019-18408):
  archive_read_format_rar_read_data in archive_read_support_format_rar.c in
  libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED
  situation, related to Ppmd7_DecodeSymbol.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-11-03 13:27:33 UTC
Let's stabilize 3.4.0 then.
Comment 2 Stabilization helper bot gentoo-dev 2019-11-03 15:03:29 UTC
An automated check of this bug failed - repoman reported dependency errors (43 lines truncated): 

> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: RDEPEND: amd64(default/linux/amd64/17.0) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
> dependency.bad app-arch/libarchive/libarchive-3.4.0.ebuild: DEPEND: amd64(default/linux/amd64/17.0/desktop) ['app-crypt/libb2[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_riscv_lp64d(-)?,abi_riscv_lp64(-)?,abi_s390_32(-)?,abi_s390_64(-)?]']
Comment 3 Stabilization helper bot gentoo-dev 2019-11-03 16:02:05 UTC
An automated check of this bug succeeded - the previous repoman errors are now resolved.
Comment 4 Aaron Bauman Gentoo Infrastructure gentoo-dev Security 2019-11-05 00:54:29 UTC
arm64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2019-11-05 08:25:03 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2019-11-05 09:27:51 UTC
x86 stable
Comment 7 Rolf Eike Beer 2019-11-06 20:15:58 UTC
sparc stable
Comment 8 Mikle Kolyada archtester Gentoo Infrastructure gentoo-dev Security 2019-11-08 08:32:33 UTC
s390 stable
Comment 9 Agostino Sarubbo gentoo-dev 2019-11-12 15:09:44 UTC
ppc64 stable
Comment 10 Rolf Eike Beer 2019-11-12 18:11:24 UTC
hppa stable