Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5418

Опубликовано: 12 сент. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 4.6
EPSS Низкий

Описание

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.

A flaw was found in the way libarchive handled hardlink archive entries of non-zero size. Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive.

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1362601libarchive: Archive Entry with type 1 (hardlink), but has a non-zero data size file overwrite

EPSS

Процентиль: 90%
0.05224
Низкий

7.5 High

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.

CVSS3: 7.5
nvd
почти 9 лет назад

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.

CVSS3: 7.5
debian
почти 9 лет назад

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlin ...

CVSS3: 7.5
github
около 3 лет назад

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.

suse-cvrf
больше 8 лет назад

Security update for libarchive

EPSS

Процентиль: 90%
0.05224
Низкий

7.5 High

CVSS3

4.6 Medium

CVSS2