PT-2016-6415 · Libarchive+5 · Libarchive+5

Kientzle

·

Publicado

2016-06-29

·

Atualizado

2024-06-15

·

CVE-2016-5418

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions libarchive versions 3.2.0 and earlier
Description The issue is related to the sandboxing code in libarchive, which incorrectly handles hardlink archive entries with non-zero data size. This could potentially allow remote attackers to write to arbitrary files by using a crafted archive file.
Recommendations For libarchive versions 3.2.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1654
CESA-2016_1844
CESA-2016_1850
CVE-2016-5418
DLA-657-1
DSA-3677-1
MGASA-2016-0318
OPENSUSE-SU-2024:10127-1
RHSA-2016:1844
RHSA-2016:1850
RHSA-2016:1852
RHSA-2016:1853
RHSA-2016_1844
RHSA-2016_1850
SUSE-SU-2016:2911-1
USN-3225-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive