Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6250

Опубликовано: 29 мая 2016
Источник: redhat
CVSS3: 7.9
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

A vulnerability was found in libarchive. An attempt to create an ISO9660 volume with 2GB or 4GB filenames could cause the application to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveNot affected
Red Hat Enterprise Linux 7libarchiveFixedRHSA-2016:184412.09.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1347085libarchive: Buffer overflow when writing large iso9660 containers

EPSS

Процентиль: 83%
0.02019
Низкий

7.9 High

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 9 лет назад

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

CVSS3: 8.6
nvd
почти 9 лет назад

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

CVSS3: 8.6
debian
почти 9 лет назад

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allo ...

CVSS3: 8.6
github
около 3 лет назад

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

suse-cvrf
больше 8 лет назад

Security update for libarchive

EPSS

Процентиль: 83%
0.02019
Низкий

7.9 High

CVSS3

4.3 Medium

CVSS2