QID 198669

Date Published: 2022-02-21

QID 198669: Ubuntu Security Notification for libarchive Vulnerabilities (USN-5291-1)

Libarchive incorrectly handled symlinks.
Libarchive incorrectly handled certain rar archives.

If auser or automated system were tricked into processing a specially craftedarchive, an attacker could possibly use this issue to change modes, times,acls, and flags on arbitrary files.
If a user or automated system were tricked into processing a speciallycrafted rar archive, an attacker could use this issue to cause libarchiveto crash, resulting in a denial of service, or possibly execute arbitrarycode.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5291-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198669

    Software Advisories
    Advisory ID Software Component Link
    USN-5291-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5291-1