Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4301

Опубликовано: 19 июн. 2016
Источник: redhat
CVSS3: 7.7
CVSS2: 6
EPSS Низкий

Описание

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

An exploitable stack based buffer overflow vulnerability exists in the mtree parse_device functionality of libarchive. A specially crafted mtree file can cause a buffer overflow resulting in memory corruption and potential code execution in the context of the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveNot affected
Red Hat Enterprise Linux 7libarchiveNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1348441libarchive: Stack buffer overflow in the mtree parse_device

EPSS

Процентиль: 80%
0.0143
Низкий

7.7 High

CVSS3

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

CVSS3: 7.8
nvd
больше 9 лет назад

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

CVSS3: 7.8
debian
больше 9 лет назад

Stack-based buffer overflow in the parse_device function in archive_re ...

CVSS3: 7.8
github
больше 3 лет назад

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

suse-cvrf
больше 9 лет назад

Security update for libarchive

EPSS

Процентиль: 80%
0.0143
Низкий

7.7 High

CVSS3

6 Medium

CVSS2