libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Sep 20, 2017 | Sep 6, 2017 |
| Debian | — | Upgrade libarchive | Dec 28, 2018 | Sep 6, 2017 |
| Gentoo Linux | — | Upgrade app-arch/libarchive. | Aug 16, 2019 | Sep 6, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libarchive | Sep 12, 2019 | Sep 6, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libarchive | Dec 18, 2019 | Sep 6, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libarchive | Nov 19, 2019 | Sep 6, 2017 |
| Oracle Solaris | — | Upgrade library/libarchive to version 3.3.3-11.4.7.0.1.2.0 on Solaris 11.4 | Mar 20, 2019 | Sep 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 5, 2017 |
| Suse | — | Upgrade libarchive-develUpgrade bsdtarUpgrade libarchive13 | May 20, 2018 | Sep 6, 2017 |
| Ubuntu | — | Upgrade libarchive13 | Aug 15, 2018 | Sep 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub