A use-after-free vulnerability was found in libarchive in RAR decoder. A crafted archive could cause the application to crash. Upstream issue: https://github.com/libarchive/libarchive/pull/1105 Upstream patch: https://github.com/libarchive/libarchive/commit/bfcfe6f04ed20db2504db8a254d1f40a1d84eb28
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1663893] Created libarchive3 tracking bugs for this issue: Affects: epel-6 [bug 1663895] Created mingw-libarchive tracking bugs for this issue: Affects: fedora-all [bug 1663894]
Statement: This issue affects the versions of libarchive as shipped with Red Hat Enterprise Linux 7. This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2298 https://access.redhat.com/errata/RHSA-2019:2298
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-1000878
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:3698 https://access.redhat.com/errata/RHSA-2019:3698