PT-2017-9736 · Libarchive+3 · Libarchive+3

Doran Moppert

·

Published

2016-11-25

·

Updated

2024-06-15

·

CVE-2016-8688

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libarchive version 3.2.1
Description The issue is related to the mtree bidder in libarchive, which does not properly track line sizes when extending the read-ahead. This allows remote attackers to cause a denial of service, resulting in a crash, by providing a crafted file. The crash is triggered by an invalid read in either the detect form or bid entry function in libarchive/archive read support format mtree.c.
Recommendations For libarchive version 3.2.1, consider restricting the use of the mtree bidder until a patch is available. As a temporary workaround, avoid using the detect form or bid entry functions in libarchive/archive read support format mtree.c to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1245
CVE-2016-8688
DLA-1600-1
DLA-661-1
OPENSUSE-SU-2024:10127-1
SUSE-SU-2016:2911-1
USN-3225-1

Affected Products

Alt Linux
Suse
Ubuntu
Libarchive