Описание
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (pz_log2_bs) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.8.7-1 |
| esm-infra-legacy/trusty | released | 3.1.2-7ubuntu2.8+esm5 |
| esm-infra-legacy/xenial | released | 3.1.2-11ubuntu0.16.04.8+esm3 |
| esm-infra/bionic | released | 3.2.2-3.1ubuntu0.7+esm3 |
| esm-infra/focal | released | 3.4.0-2ubuntu1.5+esm2 |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 3.6.0-1ubuntu1.7 |
| noble | released | 3.7.2-2ubuntu0.7 |
| questing | released | 3.7.7-0ubuntu3.2 |
| resolute | released | 3.8.5-1ubuntu2.1 |
Показывать по
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
Libarchive: libarchive: denial of service via malformed iso file processing
A flaw was found in libarchive. An Undefined Behavior vulnerability ex ...
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.
6.5 Medium
CVSS3