PT-2016-5882 · Libarchive+5 · Libarchive+5
Andrej Nemec
·
Publicado
2016-06-23
·
Atualizado
2017-11-04
·
CVE-2016-4302
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libarchive versions prior to 3.2.1
Description
A heap-based buffer overflow issue exists in the parse codes function in archive read support format rar.c, allowing remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
Recommendations
For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive