Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kientzle

#17950de 53,635
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2017-9737
7.5
2016-11-25
Libarchive · Libarchive · CVE-2016-8689
**Name of the Vulnerable Software and Affected Versions** libarchive version 3.2.1 **Description** The issue allows remote attackers to cause a denial of service, specifically an out-of-bounds read, by including multiple EmptyStream attributes in a header within a 7zip archive. This is due to a problem in the read Header function in archive read support format 7zip.c. **Recommendations** For libarchive version 3.2.1, consider updating to a newer version that addresses this issue, as using multiple EmptyStream attributes in a 7zip archive header can lead to a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2016-6415
7.5
2016-06-29
Libarchive · Libarchive · CVE-2016-5418
**Name of the Vulnerable Software and Affected Versions** libarchive versions 3.2.0 and earlier **Description** The issue is related to the sandboxing code in libarchive, which incorrectly handles hardlink archive entries with non-zero data size. This could potentially allow remote attackers to write to arbitrary files by using a crafted archive file. **Recommendations** For libarchive versions 3.2.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.