PublicDateAtUSN: 2017-09-17 Candidate: CVE-2017-14502 PublicDate: 2017-09-17 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14502 https://ubuntu.com/security/notices/USN-3859-1 Description: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=875974 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=573 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libarchive: upstream: https://github.com/libarchive/libarchive/commit/5562545b5562f6d12a4ef991fae158bf4ccf92b6 upstream_libarchive: needs-triage precise/esm_libarchive: DNE trusty_libarchive: released (3.1.2-7ubuntu2.7) trusty/esm_libarchive: released (3.1.2-7ubuntu2.7) vivid/ubuntu-core_libarchive: DNE xenial_libarchive: released (3.1.2-11ubuntu0.16.04.5) esm-infra/xenial_libarchive: released (3.1.2-11ubuntu0.16.04.5) zesty_libarchive: ignored (reached end-of-life) artful_libarchive: ignored (reached end-of-life) bionic_libarchive: released (3.2.2-3.1ubuntu0.2) cosmic_libarchive: not-affected (3.2.2-5) devel_libarchive: not-affected (3.3.3-3)