A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
| Software | From | Fixed in |
|---|---|---|
| libarchive / libarchive | - | 3.8.0 |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| redhat / enterprise_linux | 6.0 | 6.0.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| redhat / openshift_container_platform | 4.0 | 4.0.x |
| redhat / enterprise_linux | 9.0 | 9.0.x |
| redhat / enterprise_linux | 10.0 | 10.0.x |