BSA-2021-1487
21556
10 May 2021
10 May 2021
Closed
Medium
6.5
N/A
CVE-2017-14503
Summary Security Advisory ID : BSA-2021-1487 Component : Libarchive Revision : 1.0
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
Affected Products
Brocade SANnav versions before SANnav 2.1.1
Products Confirmed Not Vulnerable
No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Solution
A security update has been provided in Brocade SANnav 2.1.1 and higher releases.
Credit
This issue was discovered through security testing.
Revision History
| Version | Change | Date |
|---|---|---|
| 1.0 | Initial Publication | May 10, 2021 |