A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.
| Software | From | Fixed in |
|---|---|---|
| libarchive / libarchive | - | 3.8.0 |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| redhat / enterprise_linux | 6.0 | 6.0.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| redhat / openshift_container_platform | 4.0 | 4.0.x |
| redhat / enterprise_linux | 9.0 | 9.0.x |
| redhat / enterprise_linux | 10.0 | 10.0.x |