A memory leak in archivereadformatzipcleanup in archivereadsupportformatzip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVELZMAH typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
[
{
"digest": {
"length": 1062.0,
"function_hash": "7756515333309930967988121913935002536"
},
"target": {
"file": "libarchive/archive_read_support_format_zip.c",
"function": "archive_read_format_zip_cleanup"
},
"signature_type": "Function",
"id": "CVE-2019-11463-457a48a0",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libarchive/libarchive/commit/ba641f73f3d758d9032b3f0e5597a9c6e593a505"
},
{
"digest": {
"line_hashes": [
"281714433212046131149431112604978976357",
"133564199602421433980574568012685770708",
"102926465850718391217945789488812991351",
"25476202388215352787523326248138130929"
],
"threshold": 0.9
},
"target": {
"file": "libarchive/archive_read_support_format_zip.c"
},
"signature_type": "Line",
"id": "CVE-2019-11463-ce74e48b",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libarchive/libarchive/commit/ba641f73f3d758d9032b3f0e5597a9c6e593a505"
}
]