Description
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2987-1 | libarchive security update |
Debian DLA |
DLA-3202-1 | libarchive security update |
EUVD |
EUVD-2019-8847 | In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. |
Ubuntu USN |
USN-4293-1 | libarchive vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:09:39.580Z
Reserved: 2019-11-21T00:00:00.000Z
Link: CVE-2019-19221
No data.
Status : Modified
Published: 2019-11-21T23:15:13.887
Modified: 2024-11-21T04:34:21.390
Link: CVE-2019-19221
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN