CVE-2019-11463

Related Vulnerabilities: CVE-2019-11463  

Impact: Moderate Public Date: 2019-03-28 CWE: CWE-400 Bugzilla: 1702204: CVE-2019-11463 libarchive: memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c causing denial of service via crafted zip file A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive through 3.3.3 allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo.

The MITRE CVE dictionary describes this issue as:

A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive through 3.3.3 allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo.

Find out more about CVE-2019-11463 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Low
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 redhat-virtualization-host Affected
Red Hat Enterprise Linux 7 libarchive Affected
Red Hat Enterprise Linux 6 libarchive Affected