PT-2016-6415 · Libarchive+5 · Libarchive+5
Kientzle
·
Published
2016-06-29
·
Updated
2024-06-15
·
CVE-2016-5418
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libarchive versions 3.2.0 and earlier
Description
The issue is related to the sandboxing code in libarchive, which incorrectly handles hardlink archive entries with non-zero data size. This could potentially allow remote attackers to write to arbitrary files by using a crafted archive file.
Recommendations
For libarchive versions 3.2.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libarchive