A double free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash. Upstream issue: https://github.com/libarchive/libarchive/pull/1105 Upstream patch: https://github.com/libarchive/libarchive/pull/1105/commits/021efa522ad729ff0f5806c4ce53e4a6cc1daa31
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1663893] Created libarchive3 tracking bugs for this issue: Affects: epel-6 [bug 1663895] Created mingw-libarchive tracking bugs for this issue: Affects: fedora-all [bug 1663894]
Statement: This issue affects the versions of libarchive as shipped with Red Hat Enterprise Linux 7. This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2298 https://access.redhat.com/errata/RHSA-2019:2298
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-1000877
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:3698 https://access.redhat.com/errata/RHSA-2019:3698