Описание
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
A vulnerability was found in libarchive.  A specially crafted ZIP file could cause a few bytes of application memory in a 256-byte region to be disclosed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз | 
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libarchive | Not affected | ||
| Red Hat Enterprise Linux 7 | libarchive | Fixed | RHSA-2016:1844 | 12.09.2016 | 
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS3
3.5 Low
CVSS2
Связанные уязвимости
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
The process_extra function in libarchive before 3.2.0 uses the size fi ...
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
EPSS
3.5 Low
CVSS3
3.5 Low
CVSS2