CVE-2019-19221 PUBLISHED

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.

EPSS 0.08% · 23.4th percentile

Risk Scores

EPSS Score
0.08%
23.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibarchive0, 3.2.2-3.1ubuntu0.5, 3.2.2-3.1ubuntu0.4
Ubuntu:Pro:14.04:LTSlibarchive3.1.2-7ubuntu2.4, 3.1.2-7ubuntu2.6, 3.1.2-7ubuntu2.7
Ubuntu:20.04:LTSlibarchive3.4.0-1build1, 0, 3.4.0-1
Ubuntu:16.04:LTSlibarchive3.1.2-11ubuntu0.16.04.5, 3.1.2-11ubuntu0.16.04.4, 3.1.2-11ubuntu0.16.04.3

Timeline

References

Open in Interactive Console →