CVE-2019-11463: Libarchive

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.

Affected products

  • Libarchive Libarchive: before 3.4.0 (fixed in 3.4.0)

Published 2019-04-23. Last modified 2026-06-17.