CVE-2019-11463 describes a memory leak in libarchive 3.3.4-dev, specifically within the archive_read_format_zip_cleanup function, due to a typo in the development code. This vulnerability affects only users who downloaded the development code from GitHub, with official releases being unaffected. The CVSS score of 5.5 (Medium) indicates a local attack vector with low complexity, requiring user interaction, and leading to a high availability impact (denial of service). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low practical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.0CPE matchmatch criteria | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.