Bug 1059134 (CVE-2017-14502)

Summary: VUL-1: CVE-2017-14502: bsdtar,libarchive: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffersfrom an off-by-one error for UTF-16 names in RAR archives, leading to anout-of-bounds read in archive_read_format_rar_re
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P4 - Low CC: smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/192114/
Whiteboard: CVSSv2:SUSE:CVE-2017-14502:2.1:(AV:L/AC:L/Au:N/C:N/I:N/A:P) CVSSv3:SUSE:CVE-2017-14502:4.0:(AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Marcus Meissner 2017-09-18 11:47:59 UTC
CVE-2017-14502

read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers
from an off-by-one error for UTF-16 names in RAR archives, leading to an
out-of-bounds read in archive_read_format_rar_read_header.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14502
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=875974
https://github.com/libarchive/libarchive/commit/5562545b5562f6d12a4ef991fae158bf4ccf92b6
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=573
Comment 1 Marcus Meissner 2017-09-18 12:01:54 UTC
the code is in sle12 libarchive in some form but not in sle11.
Comment 2 Adrian Schröter 2018-10-10 14:50:39 UTC
fix for sle12 and sle15 on the way
Comment 4 Swamp Workflow Management 2018-10-30 17:09:23 UTC
SUSE-SU-2018:3571-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1059100,1059134,1059139
CVE References: CVE-2017-14501,CVE-2017-14502,CVE-2017-14503
Sources used:
SUSE Linux Enterprise Module for Development Tools 15 (src):    libarchive-3.3.2-3.3.2
SUSE Linux Enterprise Module for Basesystem 15 (src):    libarchive-3.3.2-3.3.2
Comment 5 Swamp Workflow Management 2018-11-07 14:10:28 UTC
SUSE-SU-2018:3640-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1032089,1037008,1037009,1057514,1059100,1059134,1059139
CVE References: CVE-2016-10209,CVE-2016-10349,CVE-2016-10350,CVE-2017-14166,CVE-2017-14501,CVE-2017-14502,CVE-2017-14503
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    libarchive-3.1.2-26.3.1
SUSE Linux Enterprise Server 12-SP3 (src):    libarchive-3.1.2-26.3.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    libarchive-3.1.2-26.3.1
Comment 6 Andreas Stieger 2018-11-09 20:02:56 UTC
done
Comment 7 Swamp Workflow Management 2018-11-09 23:08:55 UTC
openSUSE-SU-2018:3690-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1059100,1059134,1059139
CVE References: CVE-2017-14501,CVE-2017-14502,CVE-2017-14503
Sources used:
openSUSE Leap 15.0 (src):    libarchive-3.3.2-lp150.2.3.1
Comment 8 Swamp Workflow Management 2018-11-09 23:30:33 UTC
openSUSE-SU-2018:3717-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1032089,1037008,1037009,1057514,1059100,1059134,1059139
CVE References: CVE-2016-10209,CVE-2016-10349,CVE-2016-10350,CVE-2017-14166,CVE-2017-14501,CVE-2017-14502,CVE-2017-14503
Sources used:
openSUSE Leap 42.3 (src):    libarchive-3.1.2-20.3.1
Comment 9 Swamp Workflow Management 2018-12-07 11:12:22 UTC
SUSE-SU-2018:3640-2: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1032089,1037008,1037009,1057514,1059100,1059134,1059139
CVE References: CVE-2016-10209,CVE-2016-10349,CVE-2016-10350,CVE-2017-14166,CVE-2017-14501,CVE-2017-14502,CVE-2017-14503
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    libarchive-3.1.2-26.3.1
SUSE Linux Enterprise Server 12-SP4 (src):    libarchive-3.1.2-26.3.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    libarchive-3.1.2-26.3.1
Comment 10 Swamp Workflow Management 2019-11-28 20:21:19 UTC
SUSE-SU-2019:3092-1: An update that fixes 10 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1032089,1037008,1037009,1059134,1059139,1120653,1120654,1124341,1124342,1155079
CVE References: CVE-2016-10209,CVE-2016-10349,CVE-2016-10350,CVE-2017-14501,CVE-2017-14502,CVE-2018-1000877,CVE-2018-1000878,CVE-2019-1000019,CVE-2019-1000020,CVE-2019-18408
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    libarchive-3.1.2-26.6.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    libarchive-3.1.2-26.6.1
SUSE Linux Enterprise Server 12-SP5 (src):    libarchive-3.1.2-26.6.1
SUSE Linux Enterprise Server 12-SP4 (src):    libarchive-3.1.2-26.6.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    libarchive-3.1.2-26.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.