Описание
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.8.7-1 |
| esm-infra-legacy/trusty | released | 3.1.2-7ubuntu2.8+esm5 |
| esm-infra-legacy/xenial | released | 3.1.2-11ubuntu0.16.04.8+esm3 |
| esm-infra/bionic | released | 3.2.2-3.1ubuntu0.7+esm3 |
| esm-infra/focal | released | 3.4.0-2ubuntu1.5+esm2 |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 3.6.0-1ubuntu1.7 |
| noble | released | 3.7.2-2ubuntu0.7 |
| questing | released | 3.7.7-0ubuntu3.2 |
| resolute | released | 3.8.5-1ubuntu2.1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
A flaw was found in libarchive. On 32-bit systems, an integer overflow ...
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
EPSS
7.5 High
CVSS3