CVE-2019-11463
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2019
Last modified:
08/12/2020
Description
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | 3.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



