An error in the lhareadfileheader1() function (archivereadsupportformatlha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
{
"source": [
"CPE_STRING",
"REFERENCES"
],
"cpe": "cpe:2.3:a:libarchive:libarchive:3.2.2:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "3.2.2"
},
{
"last_affected": "3.2.2"
}
]
}
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1651.0,
"function_hash": "336704226165769747464089933487872960037"
},
"id": "CVE-2017-5601-0c9a258d",
"target": {
"function": "lha_read_file_header_1",
"file": "libarchive/archive_read_support_format_lha.c"
},
"source": "https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"154933373695779527317611311915132494466",
"42771799760974896591912558998750698051",
"84107349244644041201078345399127083101"
],
"threshold": 0.9
},
"id": "CVE-2017-5601-864d99df",
"target": {
"file": "libarchive/archive_read_support_format_lha.c"
},
"source": "https://github.com/libarchive/libarchive/commit/98dcbbf0bf4854bf987557e55e55fff7abbf3ea9",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5601.json"
"2026-08-07T14:48:59Z"