A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product’s official releases are unaffected.
CPE | Name | Operator | Version |
---|---|---|---|
libarchive | eq | 3.1.900a | |
libarchive | eq | 2.8.3 | |
libarchive | eq | 2.8.1 | |
libarchive | eq | 3.1.2 | |
libarchive | eq | 3.1.1 | |
libarchive | eq | 3.3.1 | |
libarchive | eq | 3.0.1b | |
libarchive | eq | 3.1.901a | |
libarchive | eq | 3.1.0 | |
libarchive | eq | 3.3.0 |