{"id":"CVE-2017-5601","details":"An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.","modified":"2026-04-02T00:12:27.351407Z","published":"2017-01-27T22:59:08.413Z","related":["MGASA-2017-0056","SUSE-SU-2022:0944-1","SUSE-SU-2022:0944-2","SUSE-SU-2022:1930-1","openSUSE-SU-2022:0944-1","openSUSE-SU-2024:13549-1"],"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1037974"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html"},{"type":"WEB","url":"https://secunia.com/secunia_research/2017-3/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95837"},{"type":"FIX","url":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libarchive/libarchive","events":[{"introduced":"0"},{"last_affected":"629358182b04d7de2316bbd29708c58ddf797fd2"},{"fixed":"98dcbbf0bf4854bf987557e55e55fff7abbf3ea9"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.2.2"}]}}],"versions":["v2.6.0","v2.6.1","v2.6.2","v2.7.0","v2.7.1","v2.8.0","v2.8.1","v2.8.2","v2.8.3","v2.8.4","v2.8.5","v3.0.0a","v3.0.1b","v3.0.2","v3.0.3","v3.0.4","v3.1.0","v3.1.1","v3.1.2","v3.1.900a","v3.1.901a","v3.2.0","v3.2.1","v3.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5601.json","vanir_signatures":[{"signature_type":"Function","deprecated":false,"id":"CVE-2017-5601-0c9a258d","target":{"function":"lha_read_file_header_1","file":"libarchive/archive_read_support_format_lha.c"},"source":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9","digest":{"length":1651,"function_hash":"336704226165769747464089933487872960037"},"signature_version":"v1"},{"signature_type":"Line","deprecated":false,"id":"CVE-2017-5601-864d99df","target":{"file":"libarchive/archive_read_support_format_lha.c"},"source":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9","digest":{"threshold":0.9,"line_hashes":["154933373695779527317611311915132494466","42771799760974896591912558998750698051","84107349244644041201078345399127083101"]},"signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}