安全公告详情

NS-SA-2019-0201

2019-10-14 19:29:28

简介

moderate: udisks2/libarchive security update

严重级别

moderate

主题

An update for udisks2/libarchive is now available for NewStart CGSL MAIN 5.04/CGSL CORE 5.04.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

udisks2: This package contains the dynamic library, which provides access to the udisksd daemon.
libarchive: Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives.


Security Fix(es):
udisks2: An uncontrolled format string vulnerability has been discovered in udisks when it mounts a filesystem with a malformed label. A local attacker may use this flaw to leak memory, make the udisks service crash, or cause other unspecified effects.(CVE-2018-17336)
udisks2: bugfix
libarchive: version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.(CVE-2018-1000877)
libarchive: version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.(CVE-2018-1000878)
libarchive: version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.(CVE-2019-1000019)
libarchive: 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.(CVE-2017-14503)
libarchive: version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploitable via the victim opening a specially crafted ISO9660 file.(CVE-2019-1000020)
libarchive: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.04.F18.

影响组件

  • udisks2
  • libarchive

影响产品

  • CGSL MAIN 5.04
  • CGSL CORE 5.04

更新包

{"fix":[{"product":"CGSL MAIN 5.04","pkgs":[{"binary":["udisks2-debuginfo-2.7.3-9.el7.x86_64.rpm","libudisks2-2.7.3-9.el7.x86_64.rpm","udisks2-iscsi-2.7.3-9.el7.x86_64.rpm","libudisks2-devel-2.7.3-9.el7.x86_64.rpm","udisks2-lsm-2.7.3-9.el7.x86_64.rpm","udisks2-lvm2-2.7.3-9.el7.x86_64.rpm","udisks2-2.7.3-9.el7.x86_64.rpm"],"source":"udisks2-2.7.3-9.el7.src.rpm"},{"binary":["libarchive-3.1.2-12.el7.x86_64.rpm","libarchive-debuginfo-3.1.2-12.el7.x86_64.rpm","libarchive-devel-3.1.2-12.el7.x86_64.rpm","bsdcpio-3.1.2-12.el7.x86_64.rpm","bsdtar-3.1.2-12.el7.x86_64.rpm"],"source":"libarchive-3.1.2-12.el7.src.rpm"}]},{"product":"CGSL CORE 5.04","pkgs":[{"binary":["libudisks2-2.7.3-9.el7.x86_64.rpm","libudisks2-devel-2.7.3-9.el7.x86_64.rpm","udisks2-2.7.3-9.el7.x86_64.rpm","udisks2-debuginfo-2.7.3-9.el7.x86_64.rpm","udisks2-iscsi-2.7.3-9.el7.x86_64.rpm","udisks2-lsm-2.7.3-9.el7.x86_64.rpm","udisks2-lvm2-2.7.3-9.el7.x86_64.rpm"],"source":"udisks2-2.7.3-9.el7.src.rpm"},{"binary":["bsdcpio-3.1.2-12.el7.x86_64.rpm","bsdtar-3.1.2-12.el7.x86_64.rpm","libarchive-3.1.2-12.el7.x86_64.rpm","libarchive-debuginfo-3.1.2-12.el7.x86_64.rpm","libarchive-devel-3.1.2-12.el7.x86_64.rpm"],"source":"libarchive-3.1.2-12.el7.src.rpm"}]}]}

CVE

参考