{"id":"CVE-2017-5601","details":"An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.","modified":"2026-08-03T14:23:48.765118Z","published":"2017-01-27T22:59:08.413Z","related":["SUSE-SU-2022:0944-1","SUSE-SU-2022:0944-2","SUSE-SU-2022:1930-1","openSUSE-SU-2022:0944-1","openSUSE-SU-2024:13549-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:libarchive:libarchive:3.2.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.2.2"},{"last_affected":"3.2.2"}],"source":"CPE_STRING","vendor_product":"libarchive:libarchive"}]},"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1037974"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00037.html"},{"type":"WEB","url":"https://secunia.com/secunia_research/2017-3/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95837"},{"type":"FIX","url":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libarchive/libarchive","events":[{"introduced":"0"},{"fixed":"98dcbbf0bf4854bf987557e55e55fff7abbf3ea9"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.2.2","v3.2.1","v3.2.0","v3.1.900a","v3.0.1b","v3.0.0a"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5601.json","vanir_signatures_modified":"2026-08-03T14:23:48Z","vanir_signatures":[{"source":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9","target":{"file":"libarchive/archive_read_support_format_lha.c","function":"lha_read_file_header_1"},"deprecated":false,"digest":{"length":1651,"function_hash":"336704226165769747464089933487872960037"},"id":"CVE-2017-5601-0c9a258d","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9","target":{"file":"libarchive/archive_read_support_format_lha.c"},"deprecated":false,"digest":{"line_hashes":["154933373695779527317611311915132494466","42771799760974896591912558998750698051","84107349244644041201078345399127083101"],"threshold":0.9},"id":"CVE-2017-5601-864d99df"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}