Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 24.04: USN-7070-1: libarchive DoS risks addressed

ubuntu
Calendar Grey October 16, 2024
Scroller Ubuntu
Ubuntu releases 24.04, 22.04, and 20.04 have been updated with libarchive patches to fix memory vulnerabilities that could result in Denial of Service (DoS) exploits.
Several security issues were fixed in libarchive.

Summary

Several security issues were fixed in libarchive.

Software Description:

- libarchive: Library to read/write archive files

Details:

It was discovered that libarchive mishandled certain memory checks,

which could result in a NULL pointer dereference. An attacker could

potentially use this issue to cause a denial of service. This issue

only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,

Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)

It was discovered that libarchive mishandled certain memory operations,

which could result in an out-of-bounds memory access. An attacker could

potentially use this issue to cause a denial of service. This issue only

affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.

(CVE-2024-48957, CVE-2024-48958)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
   libarchive13t64                 3.7.2-2ubuntu0.2

Ubuntu 22.04 LTS
   libarchive13                    3.6.0-1ubuntu1.2

Ubuntu 20.04 LTS
   libarchive13                    3.4.0-2ubuntu1.3

Ubuntu 18.04 LTS
   libarchive13                    3.2.2-3.1ubuntu0.7+esm1
                                   Available with Ubuntu Pro

Ubuntu 16.04 LTS
   libarchive13                    3.1.2-11ubuntu0.16.04.8+esm1
                                   Available with Ubuntu Pro

Ubuntu 14.04 LTS
   libarchive13                    3.1.2-7ubuntu2.8+esm3
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7070-1

  CVE-2022-36227, CVE-2024-48957, CVE-2024-48958

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7070-1

Package Information

 
 
 

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.