6.8
CVSSv2

CVE-2020-9308

Published: 20/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

archive_read_support_format_rar5.c in libarchive prior to 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libarchive libarchive

canonical ubuntu linux 18.04

canonical ubuntu linux 19.10

canonical ubuntu linux 16.04

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #951759 libarchive: CVE-2020-9308 Package: src:libarchive; Maintainer for src:libarchive is Peter Pentchev <roam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 21 Feb 2020 09:33:01 UTC Severity: important Tags: security, upstream Found in version libarchive/34 ...
Several security issues were fixed in libarchive ...