Red Hat Bugzilla – Bug 1494449
CVE-2017-14503 libarchive: Out-of-bounds read in lha_read_data_none
Last modified: 2018-09-06 01:40:06 EDT
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16. An attacker could use this flaw to cause a denial of service. Upstream issue: https://github.com/libarchive/libarchive/issues/948
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1449531]
https://github.com/libarchive/libarchive/commit/f9569c086ff29259c73790db9cbf39fe8fb9d862