Bug 1663889 (CVE-2018-1000878)

Summary: CVE-2018-1000878 libarchive: Use after free in RAR decoder resulting in a denial of service
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: databases-maint, hhorak, pkubat, praiskup, scorneli
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-06 19:20:31 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1663893, 1663894, 1663895, 1700749, 1700752    
Bug Blocks: 1663897    

Description Andrej Nemec 2019-01-07 09:35:39 UTC
A use-after-free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash.

Upstream issue:

https://github.com/libarchive/libarchive/pull/1105

Upstream patch:

https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28

Comment 1 Andrej Nemec 2019-01-07 09:39:08 UTC
Created libarchive tracking bugs for this issue:

Affects: fedora-all [bug 1663893]


Created libarchive3 tracking bugs for this issue:

Affects: epel-6 [bug 1663895]


Created mingw-libarchive tracking bugs for this issue:

Affects: fedora-all [bug 1663894]

Comment 5 Stefan Cornelius 2019-04-17 14:17:24 UTC
Statement:

This issue affects the versions of libarchive as shipped with Red Hat Enterprise Linux 7.

This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6.

Comment 7 errata-xmlrpc 2019-08-06 12:38:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2298 https://access.redhat.com/errata/RHSA-2019:2298

Comment 8 Product Security DevOps Team 2019-08-06 19:20:31 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-1000878

Comment 9 errata-xmlrpc 2019-11-05 22:05:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:3698 https://access.redhat.com/errata/RHSA-2019:3698