Wind River Support Network

HomeDefectsLINCD-1342
Fixed

LINCD-1342 : Security Advisory - libarchive - CVE-2019-20509

Created: Mar 11, 2020    Updated: Sep 13, 2022
Resolved Date: Mar 11, 2020
Found In Version: 10.20.6.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Userspace

Description

archive_read_support_format_lha.c in libarchive before 3.4.1 does not ensure valid sizes for UTF-16 input, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted LHA archive.

CREATE(Triage):(User=admin) CVE-2019-20509 (https://nvd.nist.gov/vuln/detail/CVE-2019-20509)
Live chat
Online