PT-2016-5882 · Libarchive+5 · Libarchive+5

Andrej Nemec

·

Published

2016-06-23

·

Updated

2017-11-04

·

CVE-2016-4302

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libarchive versions prior to 3.2.1
Description A heap-based buffer overflow issue exists in the parse codes function in archive read support format rar.c, allowing remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
Recommendations For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1654
CESA-2016_1844
CVE-2016-4302
DLA-554-1
DSA-3657-1
MGASA-2016-0239
OPENSUSE-SU-2016_2036-1
RHSA-2016:1844
RHSA-2016_1844
SUSE-SU-2016:1909-1
USN-3033-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive