CVE-2021-36976

EUVD-2021-23552
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
libarchivelibarchive
3.4.1 ≤
𝑥
≤ 3.5.2
appleipados
𝑥
< 15.4
appleiphone_os
𝑥
< 15.4
applemacos
𝑥
< 12.3
applewatchos
𝑥
< 8.5
splunkuniversal_forwarder
8.2.0 ≤
𝑥
< 8.2.12
splunkuniversal_forwarder
9.0.0 ≤
𝑥
< 9.0.6
splunkuniversal_forwarder
9.1.0
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
1809 (arm64, x64, x86)
1909 (arm64, x64, x86)
20H2 (arm64, x86)
21H1 (arm64, x64, x86)
21H2 (arm64, x64, x86)
Windows 11
21H2 (arm64, x64)
Windows Server
20H2 Server Core
Windows Server 2019
Server Core
Standard
Windows Server 2022
Server Core
Standard
Debian logo
Debian Releases
Debian Product
Codename
libarchive
bookworm
3.6.2-1+deb12u1
fixed
bookworm (security)
3.6.2-1+deb12u1
fixed
bullseye
no-dsa
buster
not-affected
sid
3.7.4-1.1
fixed
stretch
not-affected
trixie
3.7.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libarchive
bionic
not-affected
focal
Fixed 3.4.0-2ubuntu1.1
released
groovy
ignored
hirsute
ignored
impish
Fixed 3.4.3-2ubuntu0.1
released
jammy
Fixed 3.5.2-1ubuntu1
released
trusty
not-affected
xenial
not-affected