5.8
CVSSv2

CVE-2022-26280

Published: 28/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

Libarchive v3.6.0 exists to contain an out-of-bounds read via the component zipx_lzma_alone_init.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libarchive libarchive 3.6.0

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1008953 libarchive: CVE-2022-26280 Package: src:libarchive; Maintainer for src:libarchive is Peter Pentchev <roam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 4 Apr 2022 20:09:04 UTC Severity: important Tags: security, upstream Found in versions libarchive/ ...
Synopsis Important: Red Hat OpenShift Data Foundation 4130 security and bug fix update Type/Severity Security Advisory: Important Topic Updated images that include numerous enhancements, security, and bug fixes are now available in Red Hat Container Registry for Red Hat OpenShift Data Foundation 4130 on Red Hat Enterprise Linux 9Red Hat ...
Libarchive v360 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init ...
An out-of-bounds read flaw was found in libarchive This flaw allows an attacker who can supply a specially crafted zip file to libarchive to cause an out-of-bounds read in programs linked with libarchive, using the LZMA zip functionality The consequences depend on the specific program linked with libarchive Still, they would most likely result i ...
An out-of-bounds read flaw was found in libarchive This flaw allows an attacker who can supply a specially crafted zip file to libarchive to cause an out-of-bounds read in programs linked with libarchive, using the LZMA zip functionality The consequences depend on the specific program linked with libarchive Still, they would most likely result i ...